<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2015-09-03T06:26:53.675-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:29248" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:0803 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2015-0803.html" ref_id="RHSA-2015:0803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2596" ref_id="CVE-2013-2596"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5471" ref_id="CVE-2014-5471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5472" ref_id="CVE-2014-5472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8159" ref_id="CVE-2014-8159"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:55:20">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:36.974-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:30.497-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:24.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139814"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139245"/>
          <criterion comment="kernel-debug-debuginfo is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139592"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139594"/>
          <criterion comment="kernel-debuginfo is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139816"/>
          <criterion comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139745"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139355"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139839"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139855"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139760"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139845"/>
          <criterion comment="perf-debuginfo is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:140038"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139497"/>
          <criterion comment="python-perf-debuginfo is earlier than 0:2.6.32-358.59.1.el6" test_ref="oval:org.mitre.oval:tst:139820"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29140" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:0808 -- java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2015-0808.html" ref_id="RHSA-2015:0808"/>
        <reference source="CESA-2015:0808" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021065.html" ref_id="CESA-2015:0808-CentOS 7"/>
        <reference source="CESA-2015:0808" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021068.html" ref_id="CESA-2015:0808-CentOS 6"/>
        <reference source="CESA-2015:0808" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021073.html" ref_id="CESA-2015:0808-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1080" ref_id="CVE-2005-1080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0460" ref_id="CVE-2015-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0469" ref_id="CVE-2015-0469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0477" ref_id="CVE-2015-0477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0478" ref_id="CVE-2015-0478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0480" ref_id="CVE-2015-0480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0488" ref_id="CVE-2015-0488"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.
An off-by-one flaw, leading to a buffer overflow, was found in the font
parsing code in the 2D component in OpenJDK. A specially crafted font file
could possibly cause the Java Virtual Machine to execute arbitrary code,
allowing an untrusted Java application or applet to bypass Java sandbox
restrictions. (CVE-2015-0469)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:52:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:37:41.628-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:11.407-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:00.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:139368"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:139581"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:139599"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:140190"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:139601"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el5_11" test_ref="oval:org.mitre.oval:tst:139980"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:140224"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:140018"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:140221"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:139857"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:139697"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el6_6" test_ref="oval:org.mitre.oval:tst:140057"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:139981"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:139711"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:140101"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:140204"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:140123"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el7_1" test_ref="oval:org.mitre.oval:tst:140122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29136" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:0809 -- java-1.8.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.8.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2015-0809.html" ref_id="RHSA-2015:0809"/>
        <reference source="CESA-2015:0809" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021067.html" ref_id="CESA-2015:0809-CentOS 7"/>
        <reference source="CESA-2015:0809" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021070.html" ref_id="CESA-2015:0809-CentOS 6"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1080" ref_id="CVE-2005-1080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0460" ref_id="CVE-2015-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0469" ref_id="CVE-2015-0469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0470" ref_id="CVE-2015-0470"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0477" ref_id="CVE-2015-0477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0478" ref_id="CVE-2015-0478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0480" ref_id="CVE-2015-0480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0488" ref_id="CVE-2015-0488"/>
        <description>The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime
Environment and the OpenJDK 8 Java Software Development Kit.
An off-by-one flaw, leading to a buffer overflow, was found in the font
parsing code in the 2D component in OpenJDK. A specially crafted font file
could possibly cause the Java Virtual Machine to execute arbitrary code,
allowing an untrusted Java application or applet to bypass Java sandbox
restrictions. (CVE-2015-0469)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:55:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:45.964-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:01:10.636-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:01:00.182-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.8.0-openjdk is earlier than 1:1.8.0.45-28.b13.el6_6" test_ref="oval:org.mitre.oval:tst:139360"/>
            <criterion comment="java-1.8.0-openjdk-demo is earlier than 1:1.8.0.45-28.b13.el6_6" test_ref="oval:org.mitre.oval:tst:139713"/>
            <criterion comment="java-1.8.0-openjdk-devel is earlier than 1:1.8.0.45-28.b13.el6_6" test_ref="oval:org.mitre.oval:tst:139222"/>
            <criterion comment="java-1.8.0-openjdk-headless is earlier than 1:1.8.0.45-28.b13.el6_6" test_ref="oval:org.mitre.oval:tst:139277"/>
            <criterion comment="java-1.8.0-openjdk-javadoc is earlier than 1:1.8.0.45-28.b13.el6_6" test_ref="oval:org.mitre.oval:tst:139971"/>
            <criterion comment="java-1.8.0-openjdk-src is earlier than 1:1.8.0.45-28.b13.el6_6" test_ref="oval:org.mitre.oval:tst:139729"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="java-1.8.0-openjdk-debuginfo is earlier than 1:1.8.0.45-28.b13.el6_6" test_ref="oval:org.mitre.oval:tst:140028"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.8.0-openjdk is earlier than 1:1.8.0.45-30.b13.el7_1" test_ref="oval:org.mitre.oval:tst:139811"/>
            <criterion comment="java-1.8.0-openjdk-accessibility is earlier than 1:1.8.0.45-30.b13.el7_1" test_ref="oval:org.mitre.oval:tst:139924"/>
            <criterion comment="java-1.8.0-openjdk-demo is earlier than 1:1.8.0.45-30.b13.el7_1" test_ref="oval:org.mitre.oval:tst:140012"/>
            <criterion comment="java-1.8.0-openjdk-devel is earlier than 1:1.8.0.45-30.b13.el7_1" test_ref="oval:org.mitre.oval:tst:139892"/>
            <criterion comment="java-1.8.0-openjdk-headless is earlier than 1:1.8.0.45-30.b13.el7_1" test_ref="oval:org.mitre.oval:tst:139726"/>
            <criterion comment="java-1.8.0-openjdk-javadoc is earlier than 1:1.8.0.45-30.b13.el7_1" test_ref="oval:org.mitre.oval:tst:139717"/>
            <criterion comment="java-1.8.0-openjdk-src is earlier than 1:1.8.0.45-30.b13.el7_1" test_ref="oval:org.mitre.oval:tst:139991"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="java-1.8.0-openjdk-debuginfo is earlier than 1:1.8.0.45-30.b13.el7_1" test_ref="oval:org.mitre.oval:tst:139969"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28702" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:0998-01 -- Redhat qemu-kvm, qemu-guest-agent</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>qemu-kvm</product>
          <product>qemu-guest-agent</product>
        </affected>
        <reference source="VENDOR" ref_url="https://www.redhat.com/archives/rhsa-announce/2015-May/msg00011.html" ref_id="RHSA-2015:0998-01"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456" ref_id="CVE-2015-3456"/>
        <description>KVM  is a full virtualization solution for Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the user-space component for running virtual machines using KVM. An out-of-bounds memory access flaw was found in the way QEMU"s virtual Floppy Disk Controller  handled FIFO buffer access while processing certain FDC commands. A privileged guest user could use this flaw to crash the guest or, potentially, execute arbitrary code on the host with the privileges of the host"s QEMU process corresponding to the guest.  Red Hat would like to thank Jason Geffner of CrowdStrike for reporting this issue. All qemu-kvm users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-02T15:20:15">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-03T12:30:16.686-04:00">DRAFT</status_change>
            <status_change date="2015-06-22T04:00:44.216-04:00">INTERIM</status_change>
            <status_change date="2015-07-13T04:00:12.689-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Package Section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.448.el6_6.3" test_ref="oval:org.mitre.oval:tst:138661"/>
          <criterion comment="qemu-kvm-debuginfo is earlier than 2:0.12.1.2-2.448.el6_6.3" test_ref="oval:org.mitre.oval:tst:138836"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.448.el6_6.3" test_ref="oval:org.mitre.oval:tst:138926"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.448.el6_6.3" test_ref="oval:org.mitre.oval:tst:138677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28661" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1974 -- rpm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <product>rpm</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1974.html" ref_id="RHSA-2014:1974"/>
        <reference source="CESA-2014:1974-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020818.html" ref_id="CESA-2014:1974-CentOS 6"/>
        <reference source="CESA-2014:1974-CentOS 5" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020819.html" ref_id="CESA-2014:1974-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6435" ref_id="CVE-2013-6435"/>
        <description>The RPM Package Manager (RPM) is a powerful command line driven package
management system capable of installing, uninstalling, verifying, querying,
and updating software packages. Each software package consists of an
archive of files along with information about the package such as its
version, description, and other information.

It was found that RPM wrote file contents to the target installation
directory under a temporary name, and verified its cryptographic signature
only after the temporary file has been written completely. Under certain
conditions, the system interprets the unverified temporary file contents
and extracts commands from it. This could allow an attacker to modify
signed RPM files in such a way that they would execute code chosen by the
attacker during package installation. (CVE-2013-6435)

This issue was discovered by Florian Weimer of Red Hat Product Security.

All rpm users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. All running applications
linked against the RPM library must be restarted for this update to take
effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:33:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:21.363-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:36.271-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:32.228-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:136922"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:136747"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:137062"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:136793"/>
            <criterion comment="rpm is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:137165"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:136878"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:137235"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="rpm-debuginfo is earlier than 0:4.4.2.3-36.el5_11" test_ref="oval:org.mitre.oval:tst:137172"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rpm is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137024"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:136811"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137066"/>
            <criterion comment="rpm-cron is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137047"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137248"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:136765"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137213"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="rpm-debuginfo is earlier than 0:4.8.0-38.el6_6" test_ref="oval:org.mitre.oval:tst:137203"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28613" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1983 -- xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1983.html" ref_id="RHSA-2014:1983"/>
        <reference source="CESA-2014:1983-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020823.html" ref_id="CESA-2014:1983-CentOS 7"/>
        <reference source="CESA-2014:1983-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020824.html" ref_id="CESA-2014:1983-CentOS 6"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8091" ref_id="CVE-2014-8091"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8092" ref_id="CVE-2014-8092"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8093" ref_id="CVE-2014-8093"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8094" ref_id="CVE-2014-8094"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8095" ref_id="CVE-2014-8095"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8096" ref_id="CVE-2014-8096"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8097" ref_id="CVE-2014-8097"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8098" ref_id="CVE-2014-8098"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8099" ref_id="CVE-2014-8099"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8100" ref_id="CVE-2014-8100"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8101" ref_id="CVE-2014-8101"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8102" ref_id="CVE-2014-8102"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8103" ref_id="CVE-2014-8103"/>
        <description>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

Multiple integer overflow flaws and out-of-bounds write flaws were found in
the way the X.Org server calculated memory requirements for certain X11
core protocol and GLX extension requests. A malicious, authenticated client
could use either of these flaws to crash the X.Org server or, potentially,
execute arbitrary code with root privileges. (CVE-2014-8092, CVE-2014-8093,
CVE-2014-8098)

It was found that the X.Org server did not properly handle SUN-DES-1
(Secure RPC) authentication credentials. A malicious, unauthenticated
client could use this flaw to crash the X.Org server by submitting a
specially crafted authentication request. (CVE-2014-8091)

Multiple out-of-bounds access flaws were found in the way the X.Org server
calculated memory requirements for certain requests. A malicious,
authenticated client could use either of these flaws to crash the X.Org
server, or leak memory contents to the client. (CVE-2014-8097)

An integer overflow flaw was found in the way the X.Org server calculated
memory requirements for certain DRI2 extension requests. A malicious,
authenticated client could use this flaw to crash the X.Org server.
(CVE-2014-8094)

Multiple out-of-bounds access flaws were found in the way the X.Org server
calculated memory requirements for certain requests. A malicious,
authenticated client could use either of these flaws to crash the X.Org
server. (CVE-2014-8095, CVE-2014-8096, CVE-2014-8099, CVE-2014-8100,
CVE-2014-8101, CVE-2014-8102, CVE-2014-8103)

All xorg-x11-server users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:33:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:29.864-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:33.736-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:30.335-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:137019"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:136669"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:137352"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:137394"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:137275"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:137387"/>
            <criterion comment="xorg-x11-server-debuginfo is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:137157"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:137254"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.15.0-25.el6_6" test_ref="oval:org.mitre.oval:tst:137234"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.15.0-7.el7_0.3" test_ref="oval:org.mitre.oval:tst:136868"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.15.0-7.el7_0.3" test_ref="oval:org.mitre.oval:tst:136582"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.15.0-7.el7_0.3" test_ref="oval:org.mitre.oval:tst:137155"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.15.0-7.el7_0.3" test_ref="oval:org.mitre.oval:tst:137300"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.15.0-7.el7_0.3" test_ref="oval:org.mitre.oval:tst:137148"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.15.0-7.el7_0.3" test_ref="oval:org.mitre.oval:tst:137386"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.15.0-7.el7_0.3" test_ref="oval:org.mitre.oval:tst:137208"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.15.0-7.el7_0.3" test_ref="oval:org.mitre.oval:tst:137191"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="xorg-x11-server-debuginfo is earlier than 0:1.15.0-7.el7_0.3" test_ref="oval:org.mitre.oval:tst:137307"/>
        </criteria>
        <criteria comment="CentOS Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server-common is earlier than 0:1.15.0-25.el6.centos" test_ref="oval:org.mitre.oval:tst:137363"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.15.0-25.el6.centos" test_ref="oval:org.mitre.oval:tst:137108"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.15.0-25.el6.centos" test_ref="oval:org.mitre.oval:tst:136605"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.15.0-25.el6.centos" test_ref="oval:org.mitre.oval:tst:137065"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.15.0-25.el6.centos" test_ref="oval:org.mitre.oval:tst:136401"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.15.0-25.el6.centos" test_ref="oval:org.mitre.oval:tst:137292"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.15.0-25.el6.centos" test_ref="oval:org.mitre.oval:tst:136768"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.15.0-25.el6.centos" test_ref="oval:org.mitre.oval:tst:137358"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28599" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:0806 -- java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2015-0806.html" ref_id="RHSA-2015:0806"/>
        <reference source="CESA-2015:0806" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021066.html" ref_id="CESA-2015:0806-CentOS 7"/>
        <reference source="CESA-2015:0806" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-April/021069.html" ref_id="CESA-2015:0806-CentOS 6"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1080" ref_id="CVE-2005-1080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0460" ref_id="CVE-2015-0460"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0469" ref_id="CVE-2015-0469"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0477" ref_id="CVE-2015-0477"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0478" ref_id="CVE-2015-0478"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0480" ref_id="CVE-2015-0480"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0488" ref_id="CVE-2015-0488"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.
An off-by-one flaw, leading to a buffer overflow, was found in the font
parsing code in the 2D component in OpenJDK. A specially crafted font file
could possibly cause the Java Virtual Machine to execute arbitrary code,
allowing an untrusted Java application or applet to bypass Java sandbox
restrictions. (CVE-2015-0469)</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-29T10:55:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-07-06T10:34:38.697-04:00">DRAFT</status_change>
            <status_change date="2015-07-27T04:00:22.240-04:00">INTERIM</status_change>
            <status_change date="2015-08-17T04:00:19.930-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.79-2.5.5.1.el6_6" test_ref="oval:org.mitre.oval:tst:139588"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.79-2.5.5.1.el6_6" test_ref="oval:org.mitre.oval:tst:139838"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.79-2.5.5.1.el6_6" test_ref="oval:org.mitre.oval:tst:139915"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.79-2.5.5.1.el6_6" test_ref="oval:org.mitre.oval:tst:139893"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.79-2.5.5.1.el6_6" test_ref="oval:org.mitre.oval:tst:139425"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="java-1.7.0-openjdk-debuginfo is earlier than 1:1.7.0.79-2.5.5.1.el6_6" test_ref="oval:org.mitre.oval:tst:139872"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.79-2.5.5.1.el7_1" test_ref="oval:org.mitre.oval:tst:139488"/>
            <criterion comment="java-1.7.0-openjdk-accessibility is earlier than 1:1.7.0.79-2.5.5.1.el7_1" test_ref="oval:org.mitre.oval:tst:140010"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.79-2.5.5.1.el7_1" test_ref="oval:org.mitre.oval:tst:139777"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.79-2.5.5.1.el7_1" test_ref="oval:org.mitre.oval:tst:139983"/>
            <criterion comment="java-1.7.0-openjdk-headless is earlier than 1:1.7.0.79-2.5.5.1.el7_1" test_ref="oval:org.mitre.oval:tst:139901"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.79-2.5.5.1.el7_1" test_ref="oval:org.mitre.oval:tst:139561"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.79-2.5.5.1.el7_1" test_ref="oval:org.mitre.oval:tst:139611"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="java-1.7.0-openjdk-debuginfo is earlier than 1:1.7.0.79-2.5.5.1.el7_1" test_ref="oval:org.mitre.oval:tst:139864"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28588" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1984 -- bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1984.html" ref_id="RHSA-2014:1984"/>
        <reference source="CESA-2014:1984-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020827.html" ref_id="CESA-2014:1984-CentOS 6"/>
        <reference source="CESA-2014:1984-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020828.html" ref_id="CESA-2014:1984-CentOS 7"/>
        <reference source="CESA-2014:1984-CentOS 5" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020829.html" ref_id="CESA-2014:1984-CentOS 5"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8500" ref_id="CVE-2014-8500"/>
        <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A denial of service flaw was found in the way BIND followed DNS
delegations. A remote attacker could use a specially crafted zone
containing a large number of referrals which, when looked up and processed,
would cause named to use excessive amounts of memory or crash.
(CVE-2014-8500)

All bind users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:32:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:33.156-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:32.517-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:137244 - Updated Linux patches with modified epoch in states." date="2015-02-02T16:00:00.461-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-23T04:01:28.627-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:55.055-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind-chroot is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136991"/>
            <criterion comment="bind-debuginfo is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137141"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137013"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137022"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136320"/>
            <criterion comment="bind is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137046"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:136841"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137052"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-25.P1.el5_11.2" test_ref="oval:org.mitre.oval:tst:137085"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136550"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:136248"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137244"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137092"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137206"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137146"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="bind-debuginfo is earlier than 32:9.8.2-0.30.rc1.el6_6.1" test_ref="oval:org.mitre.oval:tst:137117"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136944"/>
            <criterion comment="bind-chroot is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:137006"/>
            <criterion comment="bind-devel is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136436"/>
            <criterion comment="bind-libs is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:137151"/>
            <criterion comment="bind-libs-lite is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:137044"/>
            <criterion comment="bind-license is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136871"/>
            <criterion comment="bind-lite-devel is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136695"/>
            <criterion comment="bind-sdb is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136926"/>
            <criterion comment="bind-sdb-chroot is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:137048"/>
            <criterion comment="bind-utils is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:136778"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="bind-debuginfo is earlier than 32:9.9.4-14.el7_0.1" test_ref="oval:org.mitre.oval:tst:137177"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28532" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:2021 -- jasper security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>jasper</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-2021.html" ref_id="RHSA-2014:2021"/>
        <reference source="CESA-2014:2021-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020847.html" ref_id="CESA-2014:2021-CentOS 6"/>
        <reference source="CESA-2014:2021-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020848.html" ref_id="CESA-2014:2021-CentOS 7"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8137" ref_id="CVE-2014-8137"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8138" ref_id="CVE-2014-8138"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9029" ref_id="CVE-2014-9029"/>
        <description>JasPer is an implementation of Part 1 of the JPEG 2000 image compression
standard.

Multiple off-by-one flaws, leading to heap-based buffer overflows, were
found in the way JasPer decoded JPEG 2000 image files. A specially crafted
file could cause an application using JasPer to crash or, possibly, execute
arbitrary code. (CVE-2014-9029)

A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG
2000 image files. A specially crafted file could cause an application using
JasPer to crash or, possibly, execute arbitrary code. (CVE-2014-8138)

A double free flaw was found in the way JasPer parsed ICC color profiles in
JPEG 2000 image files. A specially crafted file could cause an application
using JasPer to crash or, possibly, execute arbitrary code. (CVE-2014-8137)

Red Hat would like to thank oCERT for reporting these issues. oCERT
acknowledges Jose Duart of the Google Security Team as the original
reporter.

All JasPer users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All applications using
the JasPer libraries must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:33:30">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:27.043-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:29.629-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:26.519-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jasper is earlier than 0:1.900.1-16.el6_6.2" test_ref="oval:org.mitre.oval:tst:137205"/>
            <criterion comment="jasper-devel is earlier than 0:1.900.1-16.el6_6.2" test_ref="oval:org.mitre.oval:tst:137282"/>
            <criterion comment="jasper-libs is earlier than 0:1.900.1-16.el6_6.2" test_ref="oval:org.mitre.oval:tst:137294"/>
            <criterion comment="jasper-utils is earlier than 0:1.900.1-16.el6_6.2" test_ref="oval:org.mitre.oval:tst:136997"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="jasper-debuginfo is earlier than 0:1.900.1-16.el6_6.2" test_ref="oval:org.mitre.oval:tst:137323"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="jasper is earlier than 0:1.900.1-26.el7_0.2" test_ref="oval:org.mitre.oval:tst:137067"/>
            <criterion comment="jasper-devel is earlier than 0:1.900.1-26.el7_0.2" test_ref="oval:org.mitre.oval:tst:136928"/>
            <criterion comment="jasper-libs is earlier than 0:1.900.1-26.el7_0.2" test_ref="oval:org.mitre.oval:tst:137333"/>
            <criterion comment="jasper-utils is earlier than 0:1.900.1-26.el7_0.2" test_ref="oval:org.mitre.oval:tst:137388"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="jasper-debuginfo is earlier than 0:1.900.1-26.el7_0.2" test_ref="oval:org.mitre.oval:tst:137351"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28483" version="7" class="patch">
      <metadata>
        <title>RHSA-2014:2024 -- ntp security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <product>ntp</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-2024.html" ref_id="RHSA-2014:2024"/>
        <reference source="CESA-2014:2024-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020850.html" ref_id="CESA-2014:2024-CentOS 7"/>
        <reference source="CESA-2014:2024-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020852.html" ref_id="CESA-2014:2024-CentOS 6"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9293" ref_id="CVE-2014-9293"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9294" ref_id="CVE-2014-9294"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9295" ref_id="CVE-2014-9295"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9296" ref_id="CVE-2014-9296"/>
        <description>The Network Time Protocol (NTP) is used to synchronize a computer&amp;#39;s time
with a referenced time source.

Multiple buffer overflow flaws were discovered in ntpd&amp;#39;s crypto_recv(),
ctl_putdata(), and configure() functions. A remote attacker could use
either of these flaws to send a specially crafted request packet that could
crash ntpd or, potentially, execute arbitrary code with the privileges of
the ntp user. Note: the crypto_recv() flaw requires non-default
configurations to be active, while the ctl_putdata() flaw, by default, can
only be exploited via local attackers, and the configure() flaw requires
additional authentication to exploit. (CVE-2014-9295)

It was found that ntpd automatically generated weak keys for its internal
use if no ntpdc request authentication key was specified in the ntp.conf
configuration file. A remote attacker able to match the configured IP
restrictions could guess the generated key, and possibly use it to send
ntpdc query or configuration requests. (CVE-2014-9293)

It was found that ntp-keygen used a weak method for generating MD5 keys.
This could possibly allow an attacker to guess generated MD5 keys that
could then be used to spoof an NTP client or server. Note: it is
recommended to regenerate any MD5 keys that had explicitly been generated
with ntp-keygen; the default installation does not contain such keys).
(CVE-2014-9294)

A missing return statement in the receive() function could potentially
allow a remote attacker to bypass NTP&amp;#39;s authentication mechanism.
(CVE-2014-9296)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will restart automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:33:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:31.232-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:26.104-05:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:tst:136989 - Updated States &amp; Objects" date="2015-02-02T15:56:00.526-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-23T04:01:23.387-05:00">INTERIM</status_change>
            <status_change date="2015-03-16T04:01:52.758-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:37952 - Modified 2 rpminfo_states. The signs &quot;-0&quot; were removed from the evr line." date="2015-03-23T14:39:00.545-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:40:45.293-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:17.403-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ntp is earlier than 0:4.2.6p5-2.el6_6" test_ref="oval:org.mitre.oval:tst:136989"/>
            <criterion comment="ntp-debuginfo is earlier than 0:4.2.6p5-2.el6_6" test_ref="oval:org.mitre.oval:tst:136945"/>
            <criterion comment="ntp-doc is earlier than 0:4.2.6p5-2.el6_6" test_ref="oval:org.mitre.oval:tst:137210"/>
            <criterion comment="ntp-perl is earlier than 0:4.2.6p5-2.el6_6" test_ref="oval:org.mitre.oval:tst:137045"/>
            <criterion comment="ntpdate is earlier than 0:4.2.6p5-2.el6_6" test_ref="oval:org.mitre.oval:tst:136869"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ntp is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:136291"/>
            <criterion comment="ntp-debuginfo is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:137040"/>
            <criterion comment="ntp-doc is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:137000"/>
            <criterion comment="ntp-perl is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:136400"/>
            <criterion comment="ntpdate is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:137314"/>
            <criterion comment="sntp is earlier than 0:4.2.6p5-19.el7_0" test_ref="oval:org.mitre.oval:tst:137270"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ntp is earlier than 0:4.2.6p5-19.el7.centos" test_ref="oval:org.mitre.oval:tst:137397"/>
            <criterion comment="ntpdate is earlier than 0:4.2.6p5-19.el7.centos" test_ref="oval:org.mitre.oval:tst:137163"/>
            <criterion comment="ntp-doc is earlier than 0:4.2.6p5-19.el7.centos" test_ref="oval:org.mitre.oval:tst:137233"/>
            <criterion comment="ntp-perl is earlier than 0:4.2.6p5-19.el7.centos" test_ref="oval:org.mitre.oval:tst:136943"/>
            <criterion comment="sntp is earlier than 0:4.2.6p5-19.el7.centos" test_ref="oval:org.mitre.oval:tst:137290"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ntp is earlier than 0:4.2.6p5-2.el6.centos" test_ref="oval:org.mitre.oval:tst:137309"/>
            <criterion comment="ntpdate is earlier than 0:4.2.6p5-2.el6.centos" test_ref="oval:org.mitre.oval:tst:137136"/>
            <criterion comment="ntp-doc is earlier than 0:4.2.6p5-2.el6.centos" test_ref="oval:org.mitre.oval:tst:137187"/>
            <criterion comment="ntp-perl is earlier than 0:4.2.6p5-2.el6.centos" test_ref="oval:org.mitre.oval:tst:137149"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28459" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1924 -- thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1924.html" ref_id="RHSA-2014:1924"/>
        <reference source="CESA-2014:1924-CentOS 5" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020797.html" ref_id="CESA-2014:1924-CentOS 5"/>
        <reference source="CESA-2014:1924-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020799.html" ref_id="CESA-2014:1924-CentOS 6"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1587" ref_id="CVE-2014-1587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1590" ref_id="CVE-2014-1590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1592" ref_id="CVE-2014-1592"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1593" ref_id="CVE-2014-1593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1594" ref_id="CVE-2014-1594"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1587, CVE-2014-1590, CVE-2014-1592, CVE-2014-1593)

A flaw was found in the Alarm API, which could allow applications to
schedule actions to be run in the future. A malicious web application could
use this flaw to bypass the same-origin policy. (CVE-2014-1594)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

This update disables SSL 3.0 support by default in Thunderbird. Details on
how to re-enable SSL 3.0 support are available at:
&lt;A HREF="https://access.redhat.com/articles/1284233">https://access.redhat.com/articles/1284233&lt;/A>

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Randell Jesup, Nils Ohlmeier, Jesse
Ruderman, Max Jonas Werner, Joe Vennix, Berend-Jan Wever, Abhishek Arya,
and Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.3.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.3.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:35:54.010-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:44.520-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:46.232-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="thunderbird is earlier than 0:31.3.0-1.el5_11" test_ref="oval:org.mitre.oval:tst:136206"/>
            <criterion comment="thunderbird-debuginfo is earlier than 0:31.3.0-1.el5_11" test_ref="oval:org.mitre.oval:tst:136131"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="thunderbird is earlier than 0:31.3.0-1.el6_6" test_ref="oval:org.mitre.oval:tst:136134"/>
            <criterion comment="thunderbird-debuginfo is earlier than 0:31.3.0-1.el6_6" test_ref="oval:org.mitre.oval:tst:135692"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:31.3.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:135513"/>
        </criteria>
        <criteria comment="CentOS Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criterion comment="thunderbird is earlier than 0:31.3.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:135999"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28440" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:1115-01 -- Redhat openssl</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="https://www.redhat.com/archives/rhsa-announce/2015-June/msg00019.html" ref_id="RHSA-2015:1115-01"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8176" ref_id="CVE-2014-8176"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1789" ref_id="CVE-2015-1789"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1790" ref_id="CVE-2015-1790"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1791" ref_id="CVE-2015-1791"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1792" ref_id="CVE-2015-1792"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3216" ref_id="CVE-2015-3216"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer  and Transport Layer Security  protocols, as well as a full-strength, general purpose cryptography library. An invalid free flaw was found in the way OpenSSL handled certain DTLS handshake messages. A malicious DTLS client or server could cause a DTLS server or client using OpenSSL to crash or, potentially, execute arbitrary code.  A flaw was found in the way the OpenSSL packages shipped with Red Hat Enterprise Linux 6 and 7 performed locking in the ssleay_rand_bytes function. This issue could possibly cause a multi-threaded application using OpenSSL to perform an out-of-bounds read and crash.  An out-of-bounds read flaw was found in the X509_cmp_time function of OpenSSL. A specially crafted X.509 certificate or a Certificate Revocation List  could possibly cause a TLS/SSL server or client using OpenSSL to crash.  A race condition was found in the session handling code of OpenSSL. This issue could possibly cause a multi-threaded TLS/SSL client using OpenSSL to double free session ticket data and crash.  A flaw was found in the way OpenSSL handled Cryptographic Message Syntax  messages. A CMS message with an unknown hash function identifier could cause an application using OpenSSL to enter an infinite loop.  A NULL pointer dereference was found in the way OpenSSL handled certain PKCS#7 inputs. A specially crafted PKCS#7 input with missing EncryptedContent data could cause an application using OpenSSL to crash.  Red Hat would like to thank the OpenSSL project for reporting CVE-2014-8176, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791 and CVE-2015-1792 flaws. Upstream acknowledges Praveen Kariyanahalli and Ivan Fratric as the original reporters of CVE-2014-8176, Robert Swiecki and Hanno Bock as the original reporters of CVE-2015-1789, Michal Zalewski as the original reporter of CVE-2015-1790, Emilia Kasper as the original report of CVE-2015-1791 and Johannes Bauer as the original reporter of CVE-2015-1792. All openssl users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-06-16T09:02:52-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2015-06-18T09:31:54.573-04:00">DRAFT</status_change>
            <status_change date="2015-07-06T04:00:13.256-04:00">INTERIM</status_change>
            <status_change date="2015-07-27T04:00:16.452-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Section for Red Hat Enterprise Linux 7">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="All dependent packages of openssl">
            <criterion comment="openssl is earlier than 1:1.0.1e-42.el7_1.8" test_ref="oval:org.mitre.oval:tst:138947"/>
            <criterion comment="openssl-debuginfo is earlier than 1:1.0.1e-42.el7_1.8" test_ref="oval:org.mitre.oval:tst:138987"/>
            <criterion comment="openssl-devel is earlier than 1:1.0.1e-42.el7_1.8" test_ref="oval:org.mitre.oval:tst:138952"/>
            <criterion comment="openssl-libs is earlier than 1:1.0.1e-42.el7_1.8" test_ref="oval:org.mitre.oval:tst:139010"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Section for Red Hat Enterprise Linux 6">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="All dependent packages of openssl">
            <criterion comment="openssl is earlier than 0:1.0.1e-30.el6_6.11" test_ref="oval:org.mitre.oval:tst:138175"/>
            <criterion comment="openssl-debuginfo is earlier than 0:1.0.1e-30.el6_6.11" test_ref="oval:org.mitre.oval:tst:139017"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.1e-30.el6_6.11" test_ref="oval:org.mitre.oval:tst:138540"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28438" version="3" class="patch">
      <metadata>
        <title>RHSA-2015:0092 -- glibc security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2015-0092.html" ref_id="RHSA-2015:0092"/>
        <reference source="CESA-2015:0092-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-January/020907.html" ref_id="CESA-2015:0092-CentOS 6"/>
        <reference source="CESA-2015:0092-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2015-January/020908.html" ref_id="CESA-2015:0092-CentOS 7"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0235" ref_id="CVE-2015-0235"/>
        <description>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name
Server Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

A heap-based buffer overflow was found in glibc&amp;#39;s
__nss_hostname_digits_dots() function, which is used by the gethostbyname()
and gethostbyname2() glibc function calls. A remote attacker able to make
an application call either of these functions could use this flaw to
execute arbitrary code with the permissions of the user running the
application. (CVE-2015-0235)

Red Hat would like to thank Qualys for reporting this issue.

All glibc users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2015-01-28T12:52:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-29T16:29:54.236-05:00">DRAFT</status_change>
            <status_change date="2015-02-16T04:00:07.773-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:40.854-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137634"/>
            <criterion comment="glibc-common is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137602"/>
            <criterion comment="glibc-devel is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:136840"/>
            <criterion comment="glibc-headers is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137079"/>
            <criterion comment="glibc-static is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137023"/>
            <criterion comment="glibc-utils is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137736"/>
            <criterion comment="nscd is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137192"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc-debuginfo is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137687"/>
            <criterion comment="glibc-debuginfo-common is earlier than 0:2.12-1.149.el6_6.5" test_ref="oval:org.mitre.oval:tst:137296"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.17-55.el7_0.5" test_ref="oval:org.mitre.oval:tst:137698"/>
            <criterion comment="glibc-common is earlier than 0:2.17-55.el7_0.5" test_ref="oval:org.mitre.oval:tst:137554"/>
            <criterion comment="glibc-devel is earlier than 0:2.17-55.el7_0.5" test_ref="oval:org.mitre.oval:tst:137562"/>
            <criterion comment="glibc-headers is earlier than 0:2.17-55.el7_0.5" test_ref="oval:org.mitre.oval:tst:137544"/>
            <criterion comment="glibc-static is earlier than 0:2.17-55.el7_0.5" test_ref="oval:org.mitre.oval:tst:136859"/>
            <criterion comment="glibc-utils is earlier than 0:2.17-55.el7_0.5" test_ref="oval:org.mitre.oval:tst:137283"/>
            <criterion comment="nscd is earlier than 0:2.17-55.el7_0.5" test_ref="oval:org.mitre.oval:tst:137540"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc-debuginfo is earlier than 0:2.17-55.el7_0.5" test_ref="oval:org.mitre.oval:tst:137589"/>
            <criterion comment="glibc-debuginfo-common is earlier than 0:2.17-55.el7_0.5" test_ref="oval:org.mitre.oval:tst:137730"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28435" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1870 -- libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1870.html" ref_id="RHSA-2014:1870"/>
        <reference source="CESA-2014:1870-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020768.html" ref_id="CESA-2014:1870-CentOS 6"/>
        <reference source="CESA-2014:1870-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020769.html" ref_id="CESA-2014:1870-CentOS 7"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0209" ref_id="CVE-2014-0209"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0210" ref_id="CVE-2014-0210"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0211" ref_id="CVE-2014-0211"/>
        <description>The libXfont packages provide the X.Org libXfont runtime library. X.Org is
an open source implementation of the X Window System.

A use-after-free flaw was found in the way libXfont processed certain font
files when attempting to add a new directory to the font path. A malicious,
local user could exploit this issue to potentially execute arbitrary code
with the privileges of the X.Org server. (CVE-2014-0209)

Multiple out-of-bounds write flaws were found in the way libXfont parsed
replies received from an X.org font server. A malicious X.org server could
cause an X client to crash or, possibly, execute arbitrary code with the
privileges of the X.Org server. (CVE-2014-0210, CVE-2014-0211)

Red Hat would like to thank the X.org project for reporting these issues.
Upstream acknowledges Ilja van Sprundel as the original reporter.

Users of libXfont should upgrade to these updated packages, which contain a
backported patch to resolve this issue. All running X.Org server instances
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:36:10.052-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:43.804-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:44.441-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.4.5-4.el6_6" test_ref="oval:org.mitre.oval:tst:136177"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.5-4.el6_6" test_ref="oval:org.mitre.oval:tst:136081"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="libXfont-debuginfo is earlier than 0:1.4.5-4.el6_6" test_ref="oval:org.mitre.oval:tst:135927"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libXfont is earlier than 0:1.4.7-2.el7_0" test_ref="oval:org.mitre.oval:tst:136011"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.7-2.el7_0" test_ref="oval:org.mitre.oval:tst:136003"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="libXfont-debuginfo is earlier than 0:1.4.7-2.el7_0" test_ref="oval:org.mitre.oval:tst:135699"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28385" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1999 -- mailx security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>mailx</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1999.html" ref_id="RHSA-2014:1999"/>
        <reference source="CESA-2014:1999-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020836.html" ref_id="CESA-2014:1999-CentOS 6"/>
        <reference source="CESA-2014:1999-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020837.html" ref_id="CESA-2014:1999-CentOS 7"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2771" ref_id="CVE-2004-2771"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7844" ref_id="CVE-2014-7844"/>
        <description>The mailx packages contain a mail user agent that is used to manage mail
using scripts.

A flaw was found in the way mailx handled the parsing of email addresses.
A syntactically valid email address could allow a local attacker to cause
mailx to execute arbitrary shell commands through shell meta-characters and
the direct command execution functionality. (CVE-2004-2771, CVE-2014-7844)

Note: Applications using mailx to send email to addresses obtained from
untrusted sources will still remain vulnerable to other attacks if they
accept email addresses which start with &amp;quot;-&amp;quot; (so that they can be confused
with mailx options). To counteract this issue, this update also introduces
the &amp;quot;--&amp;quot; option, which will treat the remaining command line arguments as
email addresses.

All mailx users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:33:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:22.642-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:20.906-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:18.451-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criterion comment="mailx is earlier than 0:12.4-8.el6_6" test_ref="oval:org.mitre.oval:tst:137098"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="mailx-debuginfo is earlier than 0:12.4-8.el6_6" test_ref="oval:org.mitre.oval:tst:137320"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criterion comment="mailx is earlier than 0:12.5-12.el7_0" test_ref="oval:org.mitre.oval:tst:136842"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="mailx-debuginfo is earlier than 0:12.5-12.el7_0" test_ref="oval:org.mitre.oval:tst:137183"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28374" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1803 -- mod_auth_mellon security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mod_auth_mellon</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1803.html" ref_id="RHSA-2014:1803"/>
        <reference source="CESA-2014:1803" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020737.html" ref_id="CESA-2014:1803"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8566" ref_id="CVE-2014-8566"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8567" ref_id="CVE-2014-8567"/>
        <description>mod_auth_mellon provides a SAML 2.0 authentication module for the Apache
HTTP Server.

An information disclosure flaw was found in mod_auth_mellon&amp;#39;s session
handling that could lead to sessions overlapping in memory. A remote
attacker could potentially use this flaw to obtain data from another user&amp;#39;s
session. (CVE-2014-8566)

It was found that uninitialized data could be read when processing a user&amp;#39;s
logout request. By attempting to log out, a user could possibly cause the
Apache HTTP Server to crash. (CVE-2014-8567)

Red Hat would like to thank the mod_auth_mellon team for reporting these
issues. Upstream acknowledges Matthew Slowe as the original reporter of
CVE-2014-8566.

All users of mod_auth_mellon are advised to upgrade to this updated
package, which contains a backported patch to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:38:06">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:35:58.988-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:37.466-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:40.044-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criterion comment="mod_auth_mellon is earlier than 0:0.8.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:136247"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="mod_auth_mellon-debuginfo is earlier than 0:0.8.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:136268"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28354" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1764 -- wget security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <product>wget</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1764.html" ref_id="RHSA-2014:1764"/>
        <reference source="CESA-2014:1764-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020720.html" ref_id="CESA-2014:1764-CentOS 7"/>
        <reference source="CESA-2014:1764-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020721.html" ref_id="CESA-2014:1764-CentOS 6"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4877" ref_id="CVE-2014-4877"/>
        <description>The wget package provides the GNU Wget file retrieval utility for HTTP,
HTTPS, and FTP protocols.

A flaw was found in the way Wget handled symbolic links. A malicious FTP
server could allow Wget running in the mirror mode (using the &amp;#39;-m&amp;#39; command
line option) to write an arbitrary file to a location writable to by the
user running Wget, possibly leading to code execution. (CVE-2014-4877)

Note: This update changes the default value of the --retr-symlinks option.
The file symbolic links are now traversed by default and pointed-to files
are retrieved rather than creating a symbolic link locally.

Red Hat would like to thank the GNU Wget project for reporting this issue.
Upstream acknowledges HD Moore of Rapid7, Inc as the original reporter.

All users of wget are advised to upgrade to this updated package, which
contains a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:38:07">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:36:13.909-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:34.799-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:37.815-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.12-5.el6_6.1" test_ref="oval:org.mitre.oval:tst:136313"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="wget-debuginfo is earlier than 0:1.12-5.el6_6.1" test_ref="oval:org.mitre.oval:tst:135985"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criterion comment="wget is earlier than 0:1.14-10.el7_0.1" test_ref="oval:org.mitre.oval:tst:136001"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="wget-debuginfo is earlier than 0:1.14-10.el7_0.1" test_ref="oval:org.mitre.oval:tst:135430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28313" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1873 -- libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1873.html" ref_id="RHSA-2014:1873"/>
        <reference source="CESA-2014:1873" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020771.html" ref_id="CESA-2014:1873"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3633" ref_id="CVE-2014-3633"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3657" ref_id="CVE-2014-3657"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7823" ref_id="CVE-2014-7823"/>
        <description>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems.
In addition, libvirt provides tools for remote management of
virtualized systems.

An out-of-bounds read flaw was found in the way libvirt&amp;#39;s
qemuDomainGetBlockIoTune() function looked up the disk index in a
non-persistent (live) disk configuration while a persistent disk
configuration was being indexed. A remote attacker able to establish a
read-only connection to libvirtd could use this flaw to crash libvirtd or,
potentially, leak memory from the libvirtd process. (CVE-2014-3633)

A denial of service flaw was found in the way libvirt&amp;#39;s
virConnectListAllDomains() function computed the number of used domains.
A remote attacker able to establish a read-only connection to libvirtd
could use this flaw to make any domain operations within libvirt
unresponsive. (CVE-2014-3657)

It was found that when the VIR_DOMAIN_XML_MIGRATABLE flag was used, the
QEMU driver implementation of the virDomainGetXMLDesc() function could
bypass the restrictions of the VIR_DOMAIN_XML_SECURE flag. A remote
attacker able to establish a read-only connection to libvirtd could use
this flaw to leak certain limited information from the domain XML data.
(CVE-2014-7823)

The CVE-2014-3633 issue was discovered by Luyao Huang of Red Hat.

This update also fixes the following bug:

When dumping migratable XML configuration of a domain, libvirt removes some
automatically added devices for compatibility with older libvirt releases.
If such XML is passed to libvirt as a domain XML that should be used during
migration, libvirt checks this XML for compatibility with the internally
stored configuration of the domain. However, prior to this update, these
checks failed because of devices that were missing (the same devices
libvirt removed). As a consequence, migration with user-supplied migratable
XML failed. Since this feature is used by OpenStack, migrating QEMU/KVM
domains with OpenStack always failed. With this update, before checking
domain configurations for compatibility, libvirt transforms both
user-supplied and internal configuration into a migratable form
(automatically added devices are removed) and checks those instead. Thus,
no matter whether the user-supplied configuration was generated as
migratable or not, libvirt does not err about missing devices, and
migration succeeds as expected. (BZ#1155564)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, libvirtd will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:36:00.950-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:30.269-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:33.751-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvirt is earlier than 0:0.10.2-46.el6_6.2" test_ref="oval:org.mitre.oval:tst:136112"/>
            <criterion comment="libvirt-client is earlier than 0:0.10.2-46.el6_6.2" test_ref="oval:org.mitre.oval:tst:136088"/>
            <criterion comment="libvirt-devel is earlier than 0:0.10.2-46.el6_6.2" test_ref="oval:org.mitre.oval:tst:135935"/>
            <criterion comment="libvirt-python is earlier than 0:0.10.2-46.el6_6.2" test_ref="oval:org.mitre.oval:tst:136270"/>
            <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-46.el6_6.2" test_ref="oval:org.mitre.oval:tst:136245"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="libvirt-debuginfo is earlier than 0:0.10.2-46.el6_6.2" test_ref="oval:org.mitre.oval:tst:136082"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28208" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1826 -- libvncserver security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>libvncserver</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1826.html" ref_id="RHSA-2014:1826"/>
        <reference source="CESA-2014:1826-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020747.html" ref_id="CESA-2014:1826-CentOS 6"/>
        <reference source="CESA-2014:1826-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020758.html" ref_id="CESA-2014:1826-CentOS 7"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6051" ref_id="CVE-2014-6051"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6052" ref_id="CVE-2014-6052"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6053" ref_id="CVE-2014-6053"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6054" ref_id="CVE-2014-6054"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6055" ref_id="CVE-2014-6055"/>
        <description>LibVNCServer is a library that allows for easy creation of VNC server or
client functionality.

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way screen sizes were handled by LibVNCServer. A malicious VNC
server could use this flaw to cause a client to crash or, potentially,
execute arbitrary code in the client. (CVE-2014-6051)

A NULL pointer dereference flaw was found in LibVNCServer&amp;#39;s framebuffer
setup. A malicious VNC server could use this flaw to cause a VNC client to
crash. (CVE-2014-6052)

A NULL pointer dereference flaw was found in the way LibVNCServer handled
certain ClientCutText message. A remote attacker could use this flaw to
crash the VNC server by sending a specially crafted ClientCutText message
from a VNC client. (CVE-2014-6053)

A divide-by-zero flaw was found in the way LibVNCServer handled the scaling
factor when it was set to &amp;quot;0&amp;quot;. A remote attacker could use this flaw to
crash the VNC server using a malicious VNC client. (CVE-2014-6054)

Two stack-based buffer overflow flaws were found in the way LibVNCServer
handled file transfers. A remote attacker could use this flaw to crash the
VNC server using a malicious VNC client. (CVE-2014-6055)

Red Hat would like to thank oCERT for reporting these issues. oCERT
acknowledges Nicolas Ruff as the original reporter.

All libvncserver users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
applications linked against libvncserver must be restarted for this update
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:38:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:36:05.910-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:24.234-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:28.060-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvncserver is earlier than 0:0.9.7-7.el6_6.1" test_ref="oval:org.mitre.oval:tst:136094"/>
            <criterion comment="libvncserver-devel is earlier than 0:0.9.7-7.el6_6.1" test_ref="oval:org.mitre.oval:tst:135723"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="libvncserver-debuginfo is earlier than 0:0.9.7-7.el6_6.1" test_ref="oval:org.mitre.oval:tst:135437"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvncserver is earlier than 0:0.9.9-9.el7_0.1" test_ref="oval:org.mitre.oval:tst:135403"/>
            <criterion comment="libvncserver-devel is earlier than 0:0.9.9-9.el7_0.1" test_ref="oval:org.mitre.oval:tst:136073"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="libvncserver-debuginfo is earlier than 0:0.9.9-9.el7_0.1" test_ref="oval:org.mitre.oval:tst:136251"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28142" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1911 -- ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1911.html" ref_id="RHSA-2014:1911"/>
        <reference source="CESA-2014:1911" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020791.html" ref_id="CESA-2014:1911"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8080" ref_id="CVE-2014-8080"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8090" ref_id="CVE-2014-8090"/>
        <description>Ruby is an extensible, interpreted, object-oriented, scripting language.
It has features to process text files and to perform system management
tasks.

Multiple denial of service flaws were found in the way the Ruby REXML XML
parser performed expansion of parameter entities. A specially crafted XML
document could cause REXML to use an excessive amount of CPU and memory.
(CVE-2014-8080, CVE-2014-8090)

The CVE-2014-8090 issue was discovered by Red Hat Product Security.

All ruby users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Ruby need to be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:35:53.038-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:22.674-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:26.065-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="ruby is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135837"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:136110"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135972"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:136238"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:136222"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:136229"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135988"/>
            <criterion comment="ruby-static is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:136240"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:136126"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="ruby-debuginfo is earlier than 0:1.8.7.374-3.el6_6" test_ref="oval:org.mitre.oval:tst:135732"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28139" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1948 -- nss, nss-util, and nss-softokn security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1948.html" ref_id="RHSA-2014:1948"/>
        <reference source="CESA-2014:1948-CentOS 5" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020795.html" ref_id="CESA-2014:1948-CentOS 5"/>
        <reference source="CESA-2014:1948-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020800.html" ref_id="CESA-2014:1948-CentOS 6"/>
        <reference source="CESA-2014:1948-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020802.html" ref_id="CESA-2014:1948-CentOS 7"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

This update adds support for the TLS Fallback Signaling Cipher Suite Value
(TLS_FALLBACK_SCSV), which can be used to prevent protocol downgrade
attacks against applications which re-connect using a lower SSL/TLS
protocol version when the initial connection indicating the highest
supported protocol version fails.

This can prevent a forceful downgrade of the communication to SSL 3.0.
The SSL 3.0 protocol was found to be vulnerable to the padding oracle
attack when using block cipher suites in cipher block chaining (CBC) mode.
This issue is identified as CVE-2014-3566, and also known under the alias
POODLE. This SSL 3.0 protocol flaw will not be addressed in a future
update; it is recommended that users configure their applications to
require at least TLS protocol version 1.0 for secure communication.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:39">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:35:56.040-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:22.423-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:25.255-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="nss-debuginfo is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:136028"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:135848"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:136054"/>
            <criterion comment="nss is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:135977"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-1.el5_11" test_ref="oval:org.mitre.oval:tst:135637"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135785"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135612"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135957"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135709"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135854"/>
            <criterion comment="nss-util is earlier than 0:3.16.2.3-2.el6_6" test_ref="oval:org.mitre.oval:tst:135104"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.2.3-2.el6_6" test_ref="oval:org.mitre.oval:tst:135877"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-debuginfo is earlier than 0:3.16.2.3-3.el6_6" test_ref="oval:org.mitre.oval:tst:135108"/>
            <criterion comment="nss-util-debuginfo is earlier than 0:3.16.2.3-2.el6_6" test_ref="oval:org.mitre.oval:tst:136106"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:135157"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:135718"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:135216"/>
            <criterion comment="nss-softokn is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135941"/>
            <criterion comment="nss-softokn-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136093"/>
            <criterion comment="nss-softokn-freebl is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135797"/>
            <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:135679"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:136072"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:136083"/>
            <criterion comment="nss-util is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136049"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136065"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-debuginfo is earlier than 0:3.16.2.3-2.el7_0" test_ref="oval:org.mitre.oval:tst:135936"/>
            <criterion comment="nss-softokn-debuginfo is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136085"/>
            <criterion comment="nss-util-debuginfo is earlier than 0:3.16.2.3-1.el7_0" test_ref="oval:org.mitre.oval:tst:136207"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28030" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1767 -- php security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1767.html" ref_id="RHSA-2014:1767"/>
        <reference source="CESA-2014:1767-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020723.html" ref_id="CESA-2014:1767-CentOS 6"/>
        <reference source="CESA-2014:1767-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020726.html" ref_id="CESA-2014:1767-CentOS 7"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3668" ref_id="CVE-2014-3668"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3669" ref_id="CVE-2014-3669"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3670" ref_id="CVE-2014-3670"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3710" ref_id="CVE-2014-3710"/>
        <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

A buffer overflow flaw was found in the Exif extension. A specially crafted
JPEG or TIFF file could cause a PHP application using the exif_thumbnail()
function to crash or, possibly, execute arbitrary code with the privileges
of the user running that PHP application. (CVE-2014-3670)

An integer overflow flaw was found in the way custom objects were
unserialized. Specially crafted input processed by the unserialize()
function could cause a PHP application to crash. (CVE-2014-3669)

An out-of-bounds read flaw was found in the way the File Information
(fileinfo) extension parsed Executable and Linkable Format (ELF) files.
A remote attacker could use this flaw to crash a PHP application using
fileinfo via a specially crafted ELF file. (CVE-2014-3710)

An out of bounds read flaw was found in the way the xmlrpc extension parsed
dates in the ISO 8601 format. A specially crafted XML-RPC request or
response could possibly cause a PHP application to crash. (CVE-2014-3668)

The CVE-2014-3710 issue was discovered by Francisco Alonso of Red Hat
Product Security.

All php users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:38:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:36:04.985-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:19.524-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:21.792-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136186"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136039"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135608"/>
            <criterion comment="php-common is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136099"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136018"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135989"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135948"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136079"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135975"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136167"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135950"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136184"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135796"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136252"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135803"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135971"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136208"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135739"/>
            <criterion comment="php-process is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136064"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136048"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135944"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136128"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:135993"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136260"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136318"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136316"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136221"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="php-debuginfo is earlier than 0:5.3.3-40.el6_6" test_ref="oval:org.mitre.oval:tst:136055"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136266"/>
            <criterion comment="php-bcmath is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136063"/>
            <criterion comment="php-cli is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:135894"/>
            <criterion comment="php-common is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:135736"/>
            <criterion comment="php-dba is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:135775"/>
            <criterion comment="php-devel is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136066"/>
            <criterion comment="php-embedded is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136158"/>
            <criterion comment="php-enchant is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136026"/>
            <criterion comment="php-fpm is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136113"/>
            <criterion comment="php-gd is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136305"/>
            <criterion comment="php-intl is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:135953"/>
            <criterion comment="php-ldap is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:135958"/>
            <criterion comment="php-mbstring is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136119"/>
            <criterion comment="php-mysql is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136122"/>
            <criterion comment="php-mysqlnd is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:135516"/>
            <criterion comment="php-odbc is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136195"/>
            <criterion comment="php-pdo is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:135760"/>
            <criterion comment="php-pgsql is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136172"/>
            <criterion comment="php-process is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136198"/>
            <criterion comment="php-pspell is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136101"/>
            <criterion comment="php-recode is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136225"/>
            <criterion comment="php-snmp is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:135839"/>
            <criterion comment="php-soap is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136287"/>
            <criterion comment="php-xml is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136191"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:136163"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="php-debuginfo is earlier than 0:5.4.16-23.el7_0.3" test_ref="oval:org.mitre.oval:tst:135404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27992" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1843 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1843.html" ref_id="RHSA-2014:1843"/>
        <reference source="CESA-2014:1843" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-November/020748.html" ref_id="CESA-2014:1843"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3185" ref_id="CVE-2014-3185"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3611" ref_id="CVE-2014-3611"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3645" ref_id="CVE-2014-3645"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3646" ref_id="CVE-2014-3646"/>
        <description><![CDATA[The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A race condition flaw was found in the way the Linux kernel&#39;s KVM
subsystem handled PIT (Programmable Interval Timer) emulation. A guest user
who has access to the PIT I/O ports could use this flaw to crash the host.
(CVE-2014-3611, Important)

* A memory corruption flaw was found in the way the USB ConnectTech
WhiteHEAT serial driver processed completion commands sent via USB Request
Blocks buffers. An attacker with physical access to the system could use
this flaw to crash the system or, potentially, escalate their privileges on
the system. (CVE-2014-3185, Moderate)

* It was found that the Linux kernel&#39;s KVM subsystem did not handle the VM
exits gracefully for the invept (Invalidate Translations Derived from EPT)
and invvpid (Invalidate Translations Based on VPID) instructions. On hosts
with an Intel processor and invept/invppid VM exit support, an unprivileged
guest user could use these instructions to crash the guest. (CVE-2014-3645,
CVE-2014-3646, Moderate)

Red Hat would like to thank Lars Bull of Google for reporting
CVE-2014-3611, and the Advanced Threat Research team at Intel Security for
reporting CVE-2014-3645 and CVE-2014-3646.

This update also fixes the following bugs:

* This update fixes several race conditions between PCI error recovery
callbacks and potential calls of the ifup and ifdown commands in the tg3
driver. When triggered, these race conditions could cause a kernel crash.
(BZ#1142570)

* Previously, GFS2 failed to unmount a sub-mounted GFS2 file system if its
parent was also a GFS2 file system. This problem has been fixed by adding
the appropriate d_op-&gt;d_hash() routine call for the last component of the
mount point path in the path name lookup mechanism code (namei).
(BZ#1145193)

* Due to previous changes in the virtio-net driver, a Red Hat Enterprise
Linux 6.6 guest was unable to boot with the &quot;mgr_rxbuf=off&quot; option
specified. This was caused by providing the page_to_skb() function with an
incorrect packet length in the driver&#39;s Rx path. This problem has been
fixed and the guest in the described scenario can now boot successfully.
(BZ#1148693)

* When using one of the newer IPSec Authentication Header (AH) algorithms
with Openswan, a kernel panic could occur. This happened because the
maximum truncated ICV length was too small. To fix this problem, the
MAX_AH_AUTH_LEN parameter has been set to 64. (BZ#1149083)

* A bug in the IPMI driver caused the kernel to panic when an IPMI
interface was removed using the hotmod script. The IPMI driver has been
fixed to properly clean the relevant data when removing an IPMI interface.
(BZ#1149578)

* Due to a bug in the IPMI driver, the kernel could panic when adding an
IPMI interface that was previously removed using the hotmod script.
This update fixes this bug by ensuring that the relevant shadow structure
is initialized at the right time. (BZ#1149580)

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:38:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:36:07.394-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:18.561-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:20.005-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135815"/>
            <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135672"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:136297"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:136130"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135517"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:136204"/>
            <criterion comment="kernel-firmware is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:136255"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:136062"/>
            <criterion comment="perf is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135456"/>
            <criterion comment="python-perf is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:136262"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-debug-debuginfo is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135969"/>
            <criterion comment="kernel-debuginfo is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:136293"/>
            <criterion comment="kernel-debuginfo-common-i686 is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:136109"/>
            <criterion comment="perf-debuginfo is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135807"/>
            <criterion comment="python-perf-debuginfo is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:135326"/>
            <criterion comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-504.1.3.el6" test_ref="oval:org.mitre.oval:tst:136271"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27983" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1919 -- firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1919.html" ref_id="RHSA-2014:1919"/>
        <reference source="CESA-2014:1919-CentOS 5" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020796.html" ref_id="CESA-2014:1919-CentOS 5"/>
        <reference source="CESA-2014:1919-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020798.html" ref_id="CESA-2014:1919-CentOS 6"/>
        <reference source="CESA-2014:1919-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020801.html" ref_id="CESA-2014:1919-CentOS 7"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1587" ref_id="CVE-2014-1587"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1590" ref_id="CVE-2014-1590"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1592" ref_id="CVE-2014-1592"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1593" ref_id="CVE-2014-1593"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1594" ref_id="CVE-2014-1594"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1587, CVE-2014-1590, CVE-2014-1592, CVE-2014-1593)

A flaw was found in the Alarm API, which could allow applications to
schedule actions to be run in the future. A malicious web application could
use this flaw to bypass the same-origin policy. (CVE-2014-1594)

This update disables SSL 3.0 support by default in Firefox. Details on how
to re-enable SSL 3.0 support are available at:
&lt;A HREF="https://access.redhat.com/articles/1283153">https://access.redhat.com/articles/1283153&lt;/A>

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Randell Jesup, Nils Ohlmeier, Jesse
Ruderman, Max Jonas Werner, Joe Vennix, Berend-Jan Wever, Abhishek Arya,
and Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 31.3.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 31.3.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-08T15:37:38">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-12-19T17:36:13.137-05:00">DRAFT</status_change>
            <status_change date="2015-01-05T04:00:17.552-05:00">INTERIM</status_change>
            <status_change date="2015-01-26T04:00:19.079-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:31.3.0-4.el5_11" test_ref="oval:org.mitre.oval:tst:135966"/>
            <criterion comment="firefox-debuginfo is earlier than 0:31.3.0-4.el5_11" test_ref="oval:org.mitre.oval:tst:135920"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:31.3.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:135624"/>
            <criterion comment="firefox-debuginfo is earlier than 0:31.3.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:135768"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:31.3.0-3.el7_0" test_ref="oval:org.mitre.oval:tst:135952"/>
            <criterion comment="firefox-debuginfo is earlier than 0:31.3.0-3.el7_0" test_ref="oval:org.mitre.oval:tst:135350"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:31.3.0-4.el5.centos" test_ref="oval:org.mitre.oval:tst:135742"/>
        </criteria>
        <criteria comment="CentOS Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criterion comment="firefox is earlier than 0:31.3.0-3.el6.centos" test_ref="oval:org.mitre.oval:tst:135687"/>
        </criteria>
        <criteria comment="CentOS Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criterion comment="firefox is earlier than 0:31.3.0-3.el7.centos" test_ref="oval:org.mitre.oval:tst:136031"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27703" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1997 -- kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1997.html" ref_id="RHSA-2014:1997"/>
        <reference source="CESA-2014:1997" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-December/020838.html" ref_id="CESA-2014:1997"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6657" ref_id="CVE-2012-6657"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3673" ref_id="CVE-2014-3673"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3687" ref_id="CVE-2014-3687"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3688" ref_id="CVE-2014-3688"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5471" ref_id="CVE-2014-5471"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5472" ref_id="CVE-2014-5472"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6410" ref_id="CVE-2014-6410"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9322" ref_id="CVE-2014-9322"/>
        <description><![CDATA[The kernel packages contain the Linux kernel, the core of any Linux
operating system.


* A flaw was found in the way the Linux kernel handled GS segment register
base switching when recovering from a #SS (stack segment) fault on an
erroneous return to user space. A local, unprivileged user could use this
flaw to escalate their privileges on the system. (CVE-2014-9322, Important)

* A flaw was found in the way the Linux kernel&#39;s SCTP implementation
handled malformed or duplicate Address Configuration Change Chunks
(ASCONF). A remote attacker could use either of these flaws to crash the
system. (CVE-2014-3673, CVE-2014-3687, Important)

* A flaw was found in the way the Linux kernel&#39;s SCTP implementation
handled the association&#39;s output queue. A remote attacker could send
specially crafted packets that would cause the system to use an excessive
amount of memory, leading to a denial of service. (CVE-2014-3688,
Important)

* A stack overflow flaw caused by infinite recursion was found in the way
the Linux kernel&#39;s UDF file system implementation processed indirect ICBs.
An attacker with physical access to the system could use a specially
crafted UDF image to crash the system. (CVE-2014-6410, Low)

* It was found that the Linux kernel&#39;s networking implementation did not
correctly handle the setting of the keepalive socket option on raw sockets.
A local user able to create a raw socket could use this flaw to crash the
system. (CVE-2012-6657, Low)

* It was found that the parse_rock_ridge_inode_internal() function of the
Linux kernel&#39;s ISOFS implementation did not correctly check relocated
directories when processing Rock Ridge child link (CL) tags. An attacker
with physical access to the system could use a specially crafted ISO image
to crash the system or, potentially, escalate their privileges on the
system. (CVE-2014-5471, CVE-2014-5472, Low)

Red Hat would like to thank Andy Lutomirski for reporting CVE-2014-9322.
The CVE-2014-3673 issue was discovered by Liu Wei of Red Hat.

Bug fixes:

* This update fixes a race condition issue between the sock_queue_err_skb
function and sk_forward_alloc handling in the socket error queue
(MSG_ERRQUEUE), which could occasionally cause the kernel, for example when
using PTP, to incorrectly track allocated memory for the error queue, in
which case a traceback would occur in the system log. (BZ#1155427)

* The zcrypt device driver did not detect certain crypto cards and the
related domains for crypto adapters on System z and s390x architectures.
Consequently, it was not possible to run the system on new crypto hardware.
This update enables toleration mode for such devices so that the system
can make use of newer crypto hardware. (BZ#1158311)

* After mounting and unmounting an XFS file system several times
consecutively, the umount command occasionally became unresponsive.
This was caused by the xlog_cil_force_lsn() function that was not waiting
for completion as expected. With this update, xlog_cil_force_lsn() has been
modified to correctly wait for completion, thus fixing this bug.
(BZ#1158325)

* When using the ixgbe adapter with disabled LRO and the tx-usec or rs-usec
variables set to 0, transmit interrupts could not be set lower than the
default of 8 buffered tx frames. Consequently, a delay of TCP transfer
occurred. The restriction of a minimum of 8 buffered frames has been
removed, and the TCP delay no longer occurs. (BZ#1158326)

* The offb driver has been updated for the QEMU standard VGA adapter,
fixing an incorrect displaying of colors issue. (BZ#1158328)

* Under certain circumstances, when a discovered MTU expired, the IPv6
connection became unavailable for a short period of time. This bug has been
fixed, and the connection now works as expected. (BZ#1161418)

* A low throughput occurred when using the dm-thin driver to write to
unprovisioned or shared chunks for a thin pool with the chunk size bigger
than the max_sectors_kb variable. (BZ#1161420)

* Large write workloads on thin LVs could cause the iozone and smallfile
utilities to terminate unexpectedly. (BZ#1161421)]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-12-30T11:33:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2015-01-14T20:14:18.325-05:00">DRAFT</status_change>
            <status_change date="2015-02-02T04:00:09.674-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:01:03.140-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137336"/>
            <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137400"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136990"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137348"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136848"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137305"/>
            <criterion comment="kernel-firmware is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137259"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136976"/>
            <criterion comment="perf is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137194"/>
            <criterion comment="python-perf is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137043"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-debug-debuginfo is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136957"/>
            <criterion comment="kernel-debuginfo is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137209"/>
            <criterion comment="kernel-debuginfo-common-i686 is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137297"/>
            <criterion comment="perf-debuginfo is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:136931"/>
            <criterion comment="python-perf-debuginfo is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137082"/>
            <criterion comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-504.3.3.el6" test_ref="oval:org.mitre.oval:tst:137008"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27229" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1319: xerces-j2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>xerces-j2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1319-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1319.html"/>
        <reference source="CESA" ref_id="CESA-2014:1319"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <description>Apache Xerces for Java (Xerces-J) is a high performance, standards
compliant, validating XML parser written in Java. The xerces-j2 packages
provide Xerces-J version 2.

A resource consumption issue was found in the way Xerces-J handled XML
declarations. A remote attacker could use an XML document with a specially
crafted declaration using a long pseudo-attribute name that, when parsed by
an application using Xerces-J, would cause that application to use an
excessive amount of CPU. (CVE-2013-4002)

All xerces-j2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Applications using the
Xerces-J must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-13T11:47:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-24T13:13:15.049-04:00">DRAFT</status_change>
            <status_change date="2014-11-10T04:02:30.780-05:00">INTERIM</status_change>
            <status_change date="2014-12-01T04:01:05.430-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xerces-j2 is earlier than 0:2.7.1-12.7.el6_5" test_ref="oval:org.mitre.oval:tst:124920"/>
            <criterion comment="xerces-j2-demo is earlier than 0:2.7.1-12.7.el6_5" test_ref="oval:org.mitre.oval:tst:125521"/>
            <criterion comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-12.7.el6_5" test_ref="oval:org.mitre.oval:tst:125812"/>
            <criterion comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-12.7.el6_5" test_ref="oval:org.mitre.oval:tst:125840"/>
            <criterion comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-12.7.el6_5" test_ref="oval:org.mitre.oval:tst:125893"/>
            <criterion comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-12.7.el6_5" test_ref="oval:org.mitre.oval:tst:125678"/>
            <criterion comment="xerces-j2-scripts is earlier than 0:2.7.1-12.7.el6_5" test_ref="oval:org.mitre.oval:tst:125837"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xerces-j2 is earlier than 0:2.11.0-17.el7_0" test_ref="oval:org.mitre.oval:tst:125674"/>
            <criterion comment="xerces-j2-demo is earlier than 0:2.11.0-17.el7_0" test_ref="oval:org.mitre.oval:tst:125800"/>
            <criterion comment="xerces-j2-javadoc is earlier than 0:2.11.0-17.el7_0" test_ref="oval:org.mitre.oval:tst:125796"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27217" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1530 -- Red Hat Enterprise Linux 6 kernel security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1530.html" ref_id="RHSA-2011:1530"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1020" ref_id="CVE-2011-1020"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3347" ref_id="CVE-2011-3347"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3638" ref_id="CVE-2011-3638"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4110" ref_id="CVE-2011-4110"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* The proc file system could allow a local, unprivileged user to obtain
sensitive information or possibly cause integrity issues. (CVE-2011-1020,
Moderate)

* Non-member VLAN (virtual LAN) packet handling for interfaces in
promiscuous mode and also using the be2net driver could allow an attacker
on the local network to cause a denial of service. (CVE-2011-3347,
Moderate)

* A flaw was found in the Linux kernel in the way splitting two extents in
ext4_ext_convert_to_initialized() worked. A local, unprivileged user with
access to mount and unmount ext4 file systems could use this flaw to cause
a denial of service. (CVE-2011-3638, Moderate)

* A NULL pointer dereference flaw was found in the way the Linux kernel&amp;#39;s
key management facility handled user-defined key types. A local,
unprivileged user could use the keyctl utility to cause a denial of
service. (CVE-2011-4110, Moderate)

Red Hat would like to thank Kees Cook for reporting CVE-2011-1020; Somnath
Kotur for reporting CVE-2011-3347; and Zheng Liu for reporting
CVE-2011-3638.

This update also fixes several hundred bugs and adds enhancements. Refer to
the Red Hat Enterprise Linux 6.2 Release Notes for information on the most
significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 6 users are advised to install these updated
packages, which correct these issues, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 6.2 Release Notes and
Technical Notes. The system must be rebooted for this update to take
effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:52.903-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:58.180-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:43.523-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kernel is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:126072"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:126125"/>
          <criterion comment="kernel-debug-debuginfo is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:126053"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:125698"/>
          <criterion comment="kernel-debuginfo is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:126013"/>
          <criterion comment="kernel-debuginfo-common-i686 is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:126110"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:125887"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:125342"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:126159"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:125227"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:125281"/>
          <criterion comment="perf-debuginfo is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:126223"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:126189"/>
          <criterion comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-220.el6" test_ref="oval:org.mitre.oval:tst:126135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27187" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1536 -- libguestfs security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libguestfs</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1536.html" ref_id="RHSA-2013:1536"/>
        <reference source="CESA-2013:1536" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/000983.html" ref_id="CESA-2013:1536"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4419" ref_id="CVE-2013-4419"/>
        <description>Libguestfs is a library and set of tools for accessing and modifying guest
disk images.

It was found that guestfish, which enables shell scripting and command line
access to libguestfs, insecurely created the temporary directory used to
store the network socket when started in server mode. A local attacker
could use this flaw to intercept and modify other user&amp;#39;s guestfish command,
allowing them to perform arbitrary guestfish actions with the privileges of
a different user, or use this flaw to obtain authentication credentials.
(CVE-2013-4419)

This issue was discovered by Michael Scherer of the Red Hat Regional IT
team.

These updated libguestfs packages include numerous bug fixes and
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All libguestfs users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add these
enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:15:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:47.283-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:56.089-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:42.312-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libguestfs is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:126120"/>
            <criterion comment="libguestfs-devel is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:125934"/>
            <criterion comment="libguestfs-java is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:125959"/>
            <criterion comment="libguestfs-java-devel is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:125285"/>
            <criterion comment="libguestfs-javadoc is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:125158"/>
            <criterion comment="libguestfs-tools is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:125999"/>
            <criterion comment="libguestfs-tools-c is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:126005"/>
            <criterion comment="ocaml-libguestfs is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:126144"/>
            <criterion comment="ocaml-libguestfs-devel is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:125965"/>
            <criterion comment="perl-Sys-Guestfs is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:125648"/>
            <criterion comment="python-libguestfs is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:125536"/>
            <criterion comment="ruby-libguestfs is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:126065"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="libguestfs-debuginfo is earlier than 0:1.20.11-2.el6" test_ref="oval:org.mitre.oval:tst:126057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27175" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1553 -- qemu-kvm security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1553.html" ref_id="RHSA-2013:1553"/>
        <reference source="CESA-2013:1553" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/001062.html" ref_id="CESA-2013:1553"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4344" ref_id="CVE-2013-4344"/>
        <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems that is built into the standard Red Hat
Enterprise Linux kernel. The qemu-kvm packages form the user-space
component for running virtual machines using KVM.

A buffer overflow flaw was found in the way QEMU processed the SCSI &amp;quot;REPORT
LUNS&amp;quot; command when more than 256 LUNs were specified for a single SCSI
target. A privileged guest user could use this flaw to corrupt QEMU process
memory on the host, which could potentially result in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2013-4344)

This issue was discovered by Asias He of Red Hat.

These updated qemu-kvm packages include numerous bug fixes and various
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical
Notes, linked to in the References, for information on the most significant
of these changes.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. After installing this update, shut down all running virtual
machines. Once all virtual machines have shut down, start them again for
this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:01">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:44.386-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:55.204-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:41.928-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="qemu-guest-agent is earlier than 0:0.12.1.2-2.415.el6" test_ref="oval:org.mitre.oval:tst:126102"/>
            <criterion comment="qemu-img is earlier than 0:0.12.1.2-2.415.el6" test_ref="oval:org.mitre.oval:tst:126170"/>
            <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.415.el6" test_ref="oval:org.mitre.oval:tst:126172"/>
            <criterion comment="qemu-kvm-tools is earlier than 0:0.12.1.2-2.415.el6" test_ref="oval:org.mitre.oval:tst:125985"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="qemu-kvm-debuginfo is earlier than 0:0.12.1.2-2.415.el6" test_ref="oval:org.mitre.oval:tst:125968"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27172" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1694 -- libcap security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libcap</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1694.html" ref_id="RHSA-2011:1694"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4099" ref_id="CVE-2011-4099"/>
        <description>The libcap packages provide a library and tools for getting and setting
POSIX capabilities.

It was found that capsh did not change into the new root when using the
&amp;quot;--chroot&amp;quot; option. An application started via the &amp;quot;capsh --chroot&amp;quot; command
could use this flaw to escape the chroot restrictions. (CVE-2011-4099)

This update also fixes the following bug:

* Previously, the libcap packages did not contain the capsh(1) manual page.
With this update, the capsh(1) manual page is included. (BZ#730957)

All libcap users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:15">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:08.584-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:54.894-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:41.689-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libcap is earlier than 0:2.16-5.5.el6" test_ref="oval:org.mitre.oval:tst:125836"/>
          <criterion comment="libcap-debuginfo is earlier than 0:2.16-5.5.el6" test_ref="oval:org.mitre.oval:tst:125476"/>
          <criterion comment="libcap-devel is earlier than 0:2.16-5.5.el6" test_ref="oval:org.mitre.oval:tst:126255"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27171" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1326: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1326-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1326.html"/>
        <reference source="CESA" ref_id="CESA-2014:1326"/>
        <reference source="CVE" ref_id="CVE-2014-2497" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2497.html"/>
        <reference source="CVE" ref_id="CVE-2014-3587" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3587.html"/>
        <reference source="CVE" ref_id="CVE-2014-3597" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3597.html"/>
        <reference source="CVE" ref_id="CVE-2014-4670" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4670.html"/>
        <reference source="CVE" ref_id="CVE-2014-4698" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4698.html"/>
        <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server. PHP's fileinfo module provides functions used to identify a
particular file according to the type of data contained by the file.

It was found that the fix for CVE-2012-1571 was incomplete; the File
Information (fileinfo) extension did not correctly parse certain Composite
Document Format (CDF) files. A remote attacker could use this flaw to crash
a PHP application using fileinfo via a specially crafted CDF file.
(CVE-2014-3587)

A NULL pointer dereference flaw was found in the gdImageCreateFromXpm()
function of PHP's gd extension. A remote attacker could use this flaw to
crash a PHP application using gd via a specially crafted X PixMap (XPM)
file. (CVE-2014-2497)

Multiple buffer over-read flaws were found in the php_parserr() function of
PHP. A malicious DNS server or a man-in-the-middle attacker could possibly
use this flaw to execute arbitrary code as the PHP interpreter if a PHP
application used the dns_get_record() function to perform a DNS query.
(CVE-2014-3597)

Two use-after-free flaws were found in the way PHP handled certain Standard
PHP Library (SPL) Iterators and ArrayIterators. A malicious script author
could possibly use either of these flaws to disclose certain portions of
server memory. (CVE-2014-4670, CVE-2014-4698)

The CVE-2014-3597 issue was discovered by David KutГЎlek of the Red Hat
BaseOS QE.

All php53 and php users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
the updated packages, the httpd daemon must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-13T11:47:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-24T13:13:12.836-04:00">DRAFT</status_change>
            <status_change date="2014-11-10T04:02:26.696-05:00">INTERIM</status_change>
            <status_change date="2014-12-01T04:01:00.632-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125409"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125920"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125414"/>
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125361"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125832"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125124"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:124972"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125778"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125644"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125033"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125888"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125654"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125683"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125177"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125738"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125620"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125814"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125886"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125813"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125507"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125661"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125746"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125406"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125614"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125697"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125873"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5.2" test_ref="oval:org.mitre.oval:tst:125900"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php53 is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125496"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:124943"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125461"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125724"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125739"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125711"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125184"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125520"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125784"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125741"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125173"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125519"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125455"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125877"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125516"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125911"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125902"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125011"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125705"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125105"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-24.el5" test_ref="oval:org.mitre.oval:tst:125640"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27168" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1661 -- RDMA stack security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>infinipath-psm</product>
          <product>libibverbs</product>
          <product>libmlx4</product>
          <product>librdmacm</product>
          <product>openmpi</product>
          <product>rdma</product>
          <product>ibutils</product>
          <product>mpitests</product>
          <product>mstflint</product>
          <product>perftest</product>
          <product>qperf</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1661.html" ref_id="RHSA-2013:1661"/>
        <reference source="CESA-2013:1661" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/000962.html" ref_id="CESA-2013:1661"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4516" ref_id="CVE-2012-4516"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2561" ref_id="CVE-2013-2561"/>
        <description>Red Hat Enterprise Linux includes a collection of Infiniband and iWARP
utilities, libraries and development packages for writing applications that
use Remote Direct Memory Access (RDMA) technology.

A flaw was found in the way ibutils handled temporary files. A local
attacker could use this flaw to cause arbitrary files to be overwritten as
the root user via a symbolic link attack. (CVE-2013-2561)

It was discovered that librdmacm used a static port to connect to the
ib_acm service. A local attacker able to run a specially crafted ib_acm
service on that port could use this flaw to provide incorrect address
resolution information to librmdacm applications. (CVE-2012-4516)

The CVE-2012-4516 issue was discovered by Florian Weimer of the Red Hat
Product Security Team.

This advisory updates the following packages to the latest upstream
releases, providing a number of bug fixes and enhancements over the
previous versions:

* libibverbs-1.1.7
* libmlx4-1.0.5
* librdmacm-1.0.17
* mstflint-3.0
* perftest-2.0
* qperf-0.4.9
* rdma-3.10

Several bugs have been fixed in the openmpi, mpitests, ibutils, and
infinipath-psm packages.

The most notable changes in these updated packages from the RDMA stack are
the following:

* Multiple bugs in the Message Passing Interface (MPI) test packages were
resolved, allowing more of the mpitest applications to pass on the
underlying MPI implementations.

* The libmlx4 package now includes dracut module files to ensure that any
necessary custom configuration of mlx4 port types is included in the
initramfs dracut builds.

* Multiple test programs in the perftest and qperf packages now work
properly over RoCE interfaces, or when specifying the use of rdmacm
queue pairs.

* The mstflint package has been updated to the latest upstream version,
which is now capable of burning firmware on newly released Mellanox
Connect-IB hardware.

* A compatibility problem between the openmpi and infinipath-psm packages
has been resolved with new builds of these packages.

All RDMA users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add
these enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:50">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:03.863-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:52.399-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:40.717-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libibverbs is earlier than 0:1.1.7-1.el6" test_ref="oval:org.mitre.oval:tst:125787"/>
            <criterion comment="libibverbs-devel is earlier than 0:1.1.7-1.el6" test_ref="oval:org.mitre.oval:tst:125783"/>
            <criterion comment="libibverbs-devel-static is earlier than 0:1.1.7-1.el6" test_ref="oval:org.mitre.oval:tst:126079"/>
            <criterion comment="libibverbs-utils is earlier than 0:1.1.7-1.el6" test_ref="oval:org.mitre.oval:tst:125463"/>
            <criterion comment="libmlx4 is earlier than 0:1.0.5-4.el6.1" test_ref="oval:org.mitre.oval:tst:125966"/>
            <criterion comment="libmlx4-static is earlier than 0:1.0.5-4.el6.1" test_ref="oval:org.mitre.oval:tst:126021"/>
            <criterion comment="librdmacm is earlier than 0:1.0.17-1.el6" test_ref="oval:org.mitre.oval:tst:125817"/>
            <criterion comment="librdmacm-devel is earlier than 0:1.0.17-1.el6" test_ref="oval:org.mitre.oval:tst:125914"/>
            <criterion comment="librdmacm-static is earlier than 0:1.0.17-1.el6" test_ref="oval:org.mitre.oval:tst:126001"/>
            <criterion comment="librdmacm-utils is earlier than 0:1.0.17-1.el6" test_ref="oval:org.mitre.oval:tst:126020"/>
            <criterion comment="openmpi is earlier than 0:1.5.4-2.el6" test_ref="oval:org.mitre.oval:tst:126062"/>
            <criterion comment="openmpi-devel is earlier than 0:1.5.4-2.el6" test_ref="oval:org.mitre.oval:tst:125990"/>
            <criterion comment="rdma is earlier than 0:3.10-3.el6" test_ref="oval:org.mitre.oval:tst:125747"/>
            <criterion comment="ibutils is earlier than 0:1.5.7-8.el6" test_ref="oval:org.mitre.oval:tst:125542"/>
            <criterion comment="ibutils-devel is earlier than 0:1.5.7-8.el6" test_ref="oval:org.mitre.oval:tst:126045"/>
            <criterion comment="ibutils-libs is earlier than 0:1.5.7-8.el6" test_ref="oval:org.mitre.oval:tst:125945"/>
            <criterion comment="mpitests-mvapich is earlier than 0:3.2-9.el6" test_ref="oval:org.mitre.oval:tst:125948"/>
            <criterion comment="mpitests-mvapich2 is earlier than 0:3.2-9.el6" test_ref="oval:org.mitre.oval:tst:125952"/>
            <criterion comment="mpitests-openmpi is earlier than 0:3.2-9.el6" test_ref="oval:org.mitre.oval:tst:125946"/>
            <criterion comment="perftest is earlier than 0:2.0-2.el6" test_ref="oval:org.mitre.oval:tst:125856"/>
            <criterion comment="qperf is earlier than 0:0.4.9-1.el6" test_ref="oval:org.mitre.oval:tst:126038"/>
            <criterion comment="mpitests-mvapich-psm is earlier than 0:3.2-9.el6" test_ref="oval:org.mitre.oval:tst:126060"/>
            <criterion comment="mpitests-mvapich2-psm is earlier than 0:3.2-9.el6" test_ref="oval:org.mitre.oval:tst:125171"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libibverbs-debuginfo is earlier than 0:1.1.7-1.el6" test_ref="oval:org.mitre.oval:tst:126109"/>
            <criterion comment="libmlx4-debuginfo is earlier than 0:1.0.5-4.el6.1" test_ref="oval:org.mitre.oval:tst:125324"/>
            <criterion comment="librdmacm-debuginfo is earlier than 0:1.0.17-1.el6" test_ref="oval:org.mitre.oval:tst:126023"/>
            <criterion comment="openmpi-debuginfo is earlier than 0:1.5.4-2.el6" test_ref="oval:org.mitre.oval:tst:126000"/>
            <criterion comment="ibutils-debuginfo is earlier than 0:1.5.7-8.el6" test_ref="oval:org.mitre.oval:tst:126047"/>
            <criterion comment="mpitests-debuginfo is earlier than 0:3.2-9.el6" test_ref="oval:org.mitre.oval:tst:125942"/>
            <criterion comment="perftest-debuginfo is earlier than 0:2.0-2.el6" test_ref="oval:org.mitre.oval:tst:125494"/>
            <criterion comment="qperf-debuginfo is earlier than 0:0.4.9-1.el6" test_ref="oval:org.mitre.oval:tst:125993"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="infinipath-psm is earlier than 0:3.0.1-115.1015_open.2.el6" test_ref="oval:org.mitre.oval:tst:125513"/>
            <criterion comment="infinipath-psm-devel is earlier than 0:3.0.1-115.1015_open.2.el6" test_ref="oval:org.mitre.oval:tst:126103"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27157" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1634: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1634-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1634.html"/>
        <reference source="CESA" ref_id="CESA-2014:1634"/>
        <reference source="CVE" ref_id="CVE-2014-6457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6457.html"/>
        <reference source="CVE" ref_id="CVE-2014-6502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6502.html"/>
        <reference source="CVE" ref_id="CVE-2014-6504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6504.html"/>
        <reference source="CVE" ref_id="CVE-2014-6506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6506.html"/>
        <reference source="CVE" ref_id="CVE-2014-6511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6511.html"/>
        <reference source="CVE" ref_id="CVE-2014-6512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6512.html"/>
        <reference source="CVE" ref_id="CVE-2014-6517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6517.html"/>
        <reference source="CVE" ref_id="CVE-2014-6519" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6519.html"/>
        <reference source="CVE" ref_id="CVE-2014-6531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6531.html"/>
        <reference source="CVE" ref_id="CVE-2014-6558" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6558.html"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

Multiple flaws were discovered in the Libraries, 2D, and Hotspot components
in OpenJDK. An untrusted Java application or applet could use these flaws
to bypass certain Java sandbox restrictions. (CVE-2014-6506, CVE-2014-6531,
CVE-2014-6502, CVE-2014-6511, CVE-2014-6504, CVE-2014-6519)

It was discovered that the StAX XML parser in the JAXP component in OpenJDK
performed expansion of external parameter entities even when external
entity substitution was disabled. A remote attacker could use this flaw to
perform XML eXternal Entity (XXE) attack against applications using the
StAX parser to parse untrusted XML documents. (CVE-2014-6517)

It was discovered that the DatagramSocket implementation in OpenJDK failed
to perform source address checks for packets received on a connected
socket. A remote attacker could use this flaw to have their packets
processed as if they were received from the expected source.
(CVE-2014-6512)

It was discovered that the TLS/SSL implementation in the JSSE component in
OpenJDK failed to properly verify the server identity during the
renegotiation following session resumption, making it possible for
malicious TLS/SSL servers to perform a Triple Handshake attack against
clients using JSSE and client certificate authentication. (CVE-2014-6457)

It was discovered that the CipherInputStream class implementation in
OpenJDK did not properly handle certain exceptions. This could possibly
allow an attacker to affect the integrity of an encrypted stream handled by
this class. (CVE-2014-6558)

The CVE-2014-6512 was discovered by Florian Weimer of Red Hat Product
Security.

This update also fixes the following bug:

* The TLS/SSL implementation in OpenJDK previously failed to handle
Diffie-Hellman (DH) keys with more than 1024 bits. This caused client
applications using JSSE to fail to establish TLS/SSL connections to servers
using larger DH keys during the connection handshake. This update adds
support for DH keys with size up to 2048 bits. (BZ#1148309)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:34.038-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:42.470-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:32.993-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el5_11" test_ref="oval:org.mitre.oval:tst:125374"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el5_11" test_ref="oval:org.mitre.oval:tst:124735"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el5_11" test_ref="oval:org.mitre.oval:tst:124654"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el5_11" test_ref="oval:org.mitre.oval:tst:125226"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el5_11" test_ref="oval:org.mitre.oval:tst:125213"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:125380"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:125204"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:125061"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:125178"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el7_0" test_ref="oval:org.mitre.oval:tst:125277"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125390"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125373"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125149"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125224"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el6_6" test_ref="oval:org.mitre.oval:tst:125310"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27156" version="3" class="patch">
      <metadata>
        <title>RHSA-2012:1416 -- kdelibs security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1416.html" ref_id="RHSA-2012:1416"/>
        <reference source="CESA-2012:1416" ref_url="http://lists.centos.org/pipermail/centos-announce/2012-October/018967.html" ref_id="CESA-2012:1416"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4512" ref_id="CVE-2012-4512"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4513" ref_id="CVE-2012-4513"/>
        <description>The kdelibs packages provide libraries for the K Desktop Environment
(KDE). Konqueror is a web browser.

A heap-based buffer overflow flaw was found in the way the CSS (Cascading
Style Sheets) parser in kdelibs parsed the location of the source for font
faces. A web page containing malicious content could cause an application
using kdelibs (such as Konqueror) to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2012-4512)

A heap-based buffer over-read flaw was found in the way kdelibs calculated
canvas dimensions for large images. A web page containing malicious content
could cause an application using kdelibs to crash or disclose portions of
its memory. (CVE-2012-4513)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The desktop must be restarted (log out,
then log back in) for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:10.663-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:51.863-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:40.240-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kdelibs is earlier than 0:4.3.4-14.el6_3.2" test_ref="oval:org.mitre.oval:tst:126037"/>
            <criterion comment="kdelibs-apidocs is earlier than 0:4.3.4-14.el6_3.2" test_ref="oval:org.mitre.oval:tst:126142"/>
            <criterion comment="kdelibs-common is earlier than 0:4.3.4-14.el6_3.2" test_ref="oval:org.mitre.oval:tst:126181"/>
            <criterion comment="kdelibs-devel is earlier than 0:4.3.4-14.el6_3.2" test_ref="oval:org.mitre.oval:tst:125190"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="kdelibs-debuginfo is earlier than 0:4.3.4-14.el6_3.2" test_ref="oval:org.mitre.oval:tst:126087"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27153" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1752 -- 389-ds-base security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1752.html" ref_id="RHSA-2013:1752"/>
        <reference source="CESA-2013:1752" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/001123.html" ref_id="CESA-2013:1752"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4485" ref_id="CVE-2013-4485"/>
        <description>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

It was discovered that the 389 Directory Server did not properly handle
certain Get Effective Rights (GER) search queries when the attribute list,
which is a part of the query, included several names using the &amp;#39;@&amp;#39;
character. An attacker able to submit search queries to the 389 Directory
Server could cause it to crash. (CVE-2013-4485)

All 389-ds-base users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the 389 server service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:15:37">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:41.645-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:51.627-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:40.092-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="389-ds-base is earlier than 0:1.2.11.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:126107"/>
            <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:125962"/>
            <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:126081"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="389-ds-base-debuginfo is earlier than 0:1.2.11.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:125586"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27152" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1532 -- kexec-tools security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kexec-tools</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1532.html" ref_id="RHSA-2011:1532"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3588" ref_id="CVE-2011-3588"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3589" ref_id="CVE-2011-3589"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3590" ref_id="CVE-2011-3590"/>
        <description><![CDATA[Kexec allows for booting a Linux kernel from the context of an already
running kernel.

Kdump used the SSH (Secure Shell) &quot;StrictHostKeyChecking=no&quot; option when
dumping to SSH targets, causing the target kdump server&#39;s SSH host key not
to be checked. This could make it easier for a man-in-the-middle attacker
on the local network to impersonate the kdump SSH target server and
possibly gain access to sensitive information in the vmcore dumps.
(CVE-2011-3588)

mkdumprd created initrd files with world-readable permissions. A local user
could possibly use this flaw to gain access to sensitive information, such
as the private SSH key used to authenticate to a remote server when kdump
was configured to dump to an SSH target. (CVE-2011-3589)

mkdumprd included unneeded sensitive files (such as all files from the
&quot;/root/.ssh/&quot; directory and the host&#39;s private SSH keys) in the resulting
initrd. This could lead to an information leak when initrd files were
previously created with world-readable permissions. Note: With this update,
only the SSH client configuration, known hosts files, and the SSH key
configured via the newly introduced sshkey option in &quot;/etc/kdump.conf&quot; are
included in the initrd. The default is the key generated when running the
&quot;service kdump propagate&quot; command, &quot;/root/.ssh/kdump_id_rsa&quot;.
(CVE-2011-3590)

Red Hat would like to thank Kevan Carstensen for reporting these issues.

This update also fixes several bugs and adds various enhancements.
Space precludes documenting all of these changes in this advisory.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

All kexec-tools users should upgrade to this updated package, which
contains backported patches to resolve these issues and add these
enhancements.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:46.286-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:51.215-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:39.853-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kexec-tools is earlier than 0:2.0.0-209.el6" test_ref="oval:org.mitre.oval:tst:126084"/>
          <criterion comment="kexec-tools-debuginfo is earlier than 0:2.0.0-209.el6" test_ref="oval:org.mitre.oval:tst:126267"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27150" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1620: java-1.7.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1620-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1620.html"/>
        <reference source="CESA" ref_id="CESA-2014:1620"/>
        <reference source="CVE" ref_id="CVE-2014-6457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6457.html"/>
        <reference source="CVE" ref_id="CVE-2014-6502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6502.html"/>
        <reference source="CVE" ref_id="CVE-2014-6504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6504.html"/>
        <reference source="CVE" ref_id="CVE-2014-6506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6506.html"/>
        <reference source="CVE" ref_id="CVE-2014-6511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6511.html"/>
        <reference source="CVE" ref_id="CVE-2014-6512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6512.html"/>
        <reference source="CVE" ref_id="CVE-2014-6517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6517.html"/>
        <reference source="CVE" ref_id="CVE-2014-6519" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6519.html"/>
        <reference source="CVE" ref_id="CVE-2014-6531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6531.html"/>
        <reference source="CVE" ref_id="CVE-2014-6558" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6558.html"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

Multiple flaws were discovered in the Libraries, 2D, and Hotspot components
in OpenJDK. An untrusted Java application or applet could use these flaws
to bypass certain Java sandbox restrictions. (CVE-2014-6506, CVE-2014-6531,
CVE-2014-6502, CVE-2014-6511, CVE-2014-6504, CVE-2014-6519)

It was discovered that the StAX XML parser in the JAXP component in OpenJDK
performed expansion of external parameter entities even when external
entity substitution was disabled. A remote attacker could use this flaw to
perform XML eXternal Entity (XXE) attack against applications using the
StAX parser to parse untrusted XML documents. (CVE-2014-6517)

It was discovered that the DatagramSocket implementation in OpenJDK failed
to perform source address checks for packets received on a connected
socket. A remote attacker could use this flaw to have their packets
processed as if they were received from the expected source.
(CVE-2014-6512)

It was discovered that the TLS/SSL implementation in the JSSE component in
OpenJDK failed to properly verify the server identity during the
renegotiation following session resumption, making it possible for
malicious TLS/SSL servers to perform a Triple Handshake attack against
clients using JSSE and client certificate authentication. (CVE-2014-6457)

It was discovered that the CipherInputStream class implementation in
OpenJDK did not properly handle certain exceptions. This could possibly
allow an attacker to affect the integrity of an encrypted stream handled by
this class. (CVE-2014-6558)

The CVE-2014-6512 was discovered by Florian Weimer of Red Hat Product
Security.

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

This update also fixes the following bug:

* The TLS/SSL implementation in OpenJDK previously failed to handle
Diffie-Hellman (DH) keys with more than 1024 bits. This caused client
applications using JSSE to fail to establish TLS/SSL connections to servers
using larger DH keys during the connection handshake. This update adds
support for DH keys with size up to 2048 bits. (BZ#1148309)

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:17.242-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:41.371-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:31.170-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.71-2.5.3.1.el7_0" test_ref="oval:org.mitre.oval:tst:125262"/>
            <criterion comment="java-1.7.0-openjdk-accessibility is earlier than 1:1.7.0.71-2.5.3.1.el7_0" test_ref="oval:org.mitre.oval:tst:125261"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.71-2.5.3.1.el7_0" test_ref="oval:org.mitre.oval:tst:124961"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.71-2.5.3.1.el7_0" test_ref="oval:org.mitre.oval:tst:125320"/>
            <criterion comment="java-1.7.0-openjdk-headless is earlier than 1:1.7.0.71-2.5.3.1.el7_0" test_ref="oval:org.mitre.oval:tst:125377"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.71-2.5.3.1.el7_0" test_ref="oval:org.mitre.oval:tst:125035"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.71-2.5.3.1.el7_0" test_ref="oval:org.mitre.oval:tst:125216"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.71-2.5.3.1.el6" test_ref="oval:org.mitre.oval:tst:125317"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.71-2.5.3.1.el6" test_ref="oval:org.mitre.oval:tst:125278"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.71-2.5.3.1.el6" test_ref="oval:org.mitre.oval:tst:125050"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.71-2.5.3.1.el6" test_ref="oval:org.mitre.oval:tst:125316"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.71-2.5.3.1.el6" test_ref="oval:org.mitre.oval:tst:125321"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27149" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1655: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1655-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1655.html"/>
        <reference source="CVE" ref_id="CVE-2014-3660" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3660.html"/>
        <reference source="CESA-2014:1655" ref_id="CESA-2014:1655-CentOS 7" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020701.html"/>
        <reference source="CESA-2014:1655" ref_id="CESA-2014:1655-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001482.html"/>
        <description>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

A denial of service flaw was found in libxml2, a library providing support
to read, modify and write XML and HTML files. A remote attacker could
provide a specially crafted XML file that, when processed by an application
using libxml2, would lead to excessive CPU consumption (denial of service)
based on excessive entity substitutions, even if entity substitution was
disabled, which is the parser default behavior. (CVE-2014-3660)

All libxml2 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. The desktop must be
restarted (log out, then log back in) for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:19.153-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:41.174-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:30.946-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27149 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:51.395-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:15.280-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.7.6-17.el6_6.1" test_ref="oval:org.mitre.oval:tst:125267"/>
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-17.el6_6.1" test_ref="oval:org.mitre.oval:tst:124790"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-17.el6_6.1" test_ref="oval:org.mitre.oval:tst:125031"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-17.el6_6.1" test_ref="oval:org.mitre.oval:tst:125333"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="libxml2-debuginfo is earlier than 0:2.7.6-17.el6_6.1" test_ref="oval:org.mitre.oval:tst:138154"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libxml2 is earlier than 0:2.9.1-5.el7_0.1" test_ref="oval:org.mitre.oval:tst:125403"/>
            <criterion comment="libxml2-devel is earlier than 0:2.9.1-5.el7_0.1" test_ref="oval:org.mitre.oval:tst:125229"/>
            <criterion comment="libxml2-python is earlier than 0:2.9.1-5.el7_0.1" test_ref="oval:org.mitre.oval:tst:125241"/>
            <criterion comment="libxml2-static is earlier than 0:2.9.1-5.el7_0.1" test_ref="oval:org.mitre.oval:tst:125130"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="libxml2-debuginfo is earlier than 0:2.9.1-5.el7_0.1" test_ref="oval:org.mitre.oval:tst:138130"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27147" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1749 -- libxml2 security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1749.html" ref_id="RHSA-2011:1749"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4008" ref_id="CVE-2010-4008"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4494" ref_id="CVE-2010-4494"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0216" ref_id="CVE-2011-0216"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1944" ref_id="CVE-2011-1944"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2821" ref_id="CVE-2011-2821"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2834" ref_id="CVE-2011-2834"/>
        <description>The libxml2 library is a development toolbox providing the implementation
of various XML standards. One of those standards is the XML Path Language
(XPath), which is a language for addressing parts of an XML document.

An off-by-one error, leading to a heap-based buffer overflow, was found in
the way libxml2 parsed certain XML files. A remote attacker could provide
a specially-crafted XML file that, when opened in an application linked
against libxml2, would cause the application to crash or, potentially,
execute arbitrary code with the privileges of the user running the
application. (CVE-2011-0216)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way libxml2 parsed certain XPath expressions. If an attacker
were able to supply a specially-crafted XML file to an application using
libxml2, as well as an XPath expression for that application to run against
the crafted file, it could cause the application to crash or, possibly,
execute arbitrary code. (CVE-2011-1944)

Multiple flaws were found in the way libxml2 parsed certain XPath
expressions. If an attacker were able to supply a specially-crafted XML
file to an application using libxml2, as well as an XPath expression for
that application to run against the crafted file, it could cause the
application to crash. (CVE-2010-4008, CVE-2010-4494, CVE-2011-2821,
CVE-2011-2834)

Note: Red Hat does not ship any applications that use libxml2 in a way that
would allow the CVE-2011-1944, CVE-2010-4008, CVE-2010-4494, CVE-2011-2821,
and CVE-2011-2834 flaws to be exploited; however, third-party applications
may allow XPath expressions to be passed which could trigger these flaws.

Red Hat would like to thank the Google Security Team for reporting the
CVE-2010-4008 issue. Upstream acknowledges Bui Quang Minh from Bkis as the
original reporter of CVE-2010-4008.

This update also fixes the following bugs:

* A number of patches have been applied to harden the XPath processing code
in libxml2, such as fixing memory leaks, rounding errors, XPath numbers
evaluations, and a potential error in encoding conversion. (BZ#732335)

All users of libxml2 are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. The desktop must
be restarted (log out, then log back in) for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:48.711-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:50.318-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:39.463-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libxml2 is earlier than 0:2.7.6-4.el6" test_ref="oval:org.mitre.oval:tst:125769"/>
          <criterion comment="libxml2-debuginfo is earlier than 0:2.7.6-4.el6" test_ref="oval:org.mitre.oval:tst:126231"/>
          <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.el6" test_ref="oval:org.mitre.oval:tst:126052"/>
          <criterion comment="libxml2-python is earlier than 0:2.7.6-4.el6" test_ref="oval:org.mitre.oval:tst:126157"/>
          <criterion comment="libxml2-static is earlier than 0:2.7.6-4.el6" test_ref="oval:org.mitre.oval:tst:126278"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27140" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1647: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1647-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1647.html"/>
        <reference source="CESA" ref_id="CESA-2014:1647"/>
        <reference source="CVE" ref_id="CVE-2014-1574" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1574.html"/>
        <reference source="CVE" ref_id="CVE-2014-1577" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1577.html"/>
        <reference source="CVE" ref_id="CVE-2014-1578" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1578.html"/>
        <reference source="CVE" ref_id="CVE-2014-1581" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1581.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1574, CVE-2014-1578, CVE-2014-1581, CVE-2014-1577)

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Christian Holler, David Bolter, Byron
Campen Jon Coppeard, Holger Fuhrmannek, Abhishek Arya, and regenrecht as
the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 31.2.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 31.2.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:16.023-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:40.272-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:27.458-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:31.2.0-2.el5_11" test_ref="oval:org.mitre.oval:tst:125259"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:31.2.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:125147"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:31.2.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:125043"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27125" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1626: chromium-browser security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>chromium-browser</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1626-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1626.html"/>
        <reference source="CVE" ref_id="CVE-2014-3188" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3188.html"/>
        <reference source="CVE" ref_id="CVE-2014-3189" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3189.html"/>
        <reference source="CVE" ref_id="CVE-2014-3190" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3190.html"/>
        <reference source="CVE" ref_id="CVE-2014-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3191.html"/>
        <reference source="CVE" ref_id="CVE-2014-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3192.html"/>
        <reference source="CVE" ref_id="CVE-2014-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3193.html"/>
        <reference source="CVE" ref_id="CVE-2014-3194" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3194.html"/>
        <reference source="CVE" ref_id="CVE-2014-3195" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3195.html"/>
        <reference source="CVE" ref_id="CVE-2014-3197" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3197.html"/>
        <reference source="CVE" ref_id="CVE-2014-3198" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3198.html"/>
        <reference source="CVE" ref_id="CVE-2014-3199" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3199.html"/>
        <reference source="CVE" ref_id="CVE-2014-3200" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3200.html"/>
        <description>Chromium is an open-source web browser, powered by WebKit (Blink).

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Chromium to crash or,
potentially, execute arbitrary code with the privileges of the user running
Chromium. (CVE-2014-3188, CVE-2014-3189, CVE-2014-3190, CVE-2014-3191,
CVE-2014-3192, CVE-2014-3193, CVE-2014-3194, CVE-2014-3199, CVE-2014-3200)

Several information leak flaws were found in the processing of malformed
web content. A web page containing malicious content could cause Chromium
to disclose potentially sensitive information. (CVE-2014-3195,
CVE-2014-3197, CVE-2014-3198)

All Chromium users should upgrade to these updated packages, which contain
Chromium version 38.0.2125.101, which corrects these issues. After
installing the update, Chromium must be restarted for the changes to take
effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:17.880-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:38.640-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:21.254-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="chromium-browser is earlier than 0:38.0.2125.101-2.el6_6" test_ref="oval:org.mitre.oval:tst:125165"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27107" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1364 -- kdelibs security and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1364.html" ref_id="RHSA-2011:1364"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3365" ref_id="CVE-2011-3365"/>
        <description>The kdelibs packages provide libraries for the K Desktop Environment (KDE).

An input sanitization flaw was found in the KSSL (KDE SSL Wrapper) API. An
attacker could supply a specially-crafted SSL certificate (for example, via
a web page) to an application using KSSL, such as the Konqueror web
browser, causing misleading information to be presented to the user,
possibly tricking them into accepting the certificate as valid.
(CVE-2011-3365)

This update also adds the following enhancement:

* kdelibs provided its own set of trusted Certificate Authority (CA)
certificates. This update makes kdelibs use the system set from the
ca-certificates package, instead of its own copy. (BZ#743951)

Users should upgrade to these updated packages, which contain backported
patches to correct this issue and add this enhancement. The desktop must be
restarted (log out, then log back in) for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:05.509-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:44.828-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:37.137-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="kdelibs is earlier than 0:4.3.4-11.el6_1.4" test_ref="oval:org.mitre.oval:tst:126007"/>
          <criterion comment="kdelibs-apidocs is earlier than 0:4.3.4-11.el6_1.4" test_ref="oval:org.mitre.oval:tst:125982"/>
          <criterion comment="kdelibs-common is earlier than 0:4.3.4-11.el6_1.4" test_ref="oval:org.mitre.oval:tst:126230"/>
          <criterion comment="kdelibs-debuginfo is earlier than 0:4.3.4-11.el6_1.4" test_ref="oval:org.mitre.oval:tst:126191"/>
          <criterion comment="kdelibs-devel is earlier than 0:4.3.4-11.el6_1.4" test_ref="oval:org.mitre.oval:tst:126317"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27103" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1540 -- evolution security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>cheese</product>
          <product>control-center</product>
          <product>ekiga</product>
          <product>evolution</product>
          <product>evolution-data-server</product>
          <product>evolution-exchange</product>
          <product>evolution-mapi</product>
          <product>gnome-panel</product>
          <product>gnome-python2-desktop</product>
          <product>gtkhtml3</product>
          <product>libgdata</product>
          <product>nautilus-sendto</product>
          <product>openchange</product>
          <product>pidgin</product>
          <product>planner</product>
          <product>totem</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1540.html" ref_id="RHSA-2013:1540"/>
        <reference source="CESA-2013:1540" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/000906.html" ref_id="CESA-2013:1540"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4166" ref_id="CVE-2013-4166"/>
        <description><![CDATA[Evolution is the integrated collection of email, calendaring, contact
management, communications, and personal information management (PIM) tools
for the GNOME desktop environment.

A flaw was found in the way Evolution selected GnuPG public keys when
encrypting emails. This could result in emails being encrypted with public
keys other than the one belonging to the intended recipient.
(CVE-2013-4166)

The Evolution packages have been upgraded to upstream version 2.32.3, which
provides a number of bug fixes and enhancements over the previous version.
These changes include implementation of Gnome XDG Config Folders, and
support for Exchange Web Services (EWS) protocol to connect to Microsoft
Exchange servers. EWS support has been added as a part of the
evolution-exchange packages. (BZ#883010, BZ#883014, BZ#883015, BZ#883017,
BZ#524917, BZ#524921, BZ#883044)

The gtkhtml3 packages have been upgraded to upstream version 2.32.2, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#883019)

The libgdata packages have been upgraded to upstream version 0.6.4, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#883032)

This update also fixes the following bug:

* The Exchange Calendar could not fetch the &quot;Free&quot; and &quot;Busy&quot; information
for meeting attendees when using Microsoft Exchange 2010 servers, and this
information thus could not be displayed. This happened because Microsoft
Exchange 2010 servers use more strict rules for &quot;Free&quot; and &quot;Busy&quot;
information fetching. With this update, the respective code in the
openchange packages has been modified so the &quot;Free&quot; and &quot;Busy&quot; information
fetching now complies with the fetching rules on Microsoft Exchange 2010
servers. The &quot;Free&quot; and &quot;Busy&quot; information can now be displayed as expected
in the Exchange Calendar. (BZ#665967)

All Evolution users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. All running instances of Evolution must be restarted for this
update to take effect.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:15:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:01.988-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:43.466-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:36.635-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cheese is earlier than 0:2.28.1-8.el6" test_ref="oval:org.mitre.oval:tst:125694"/>
            <criterion comment="control-center is earlier than 0:2.28.1-39.el6" test_ref="oval:org.mitre.oval:tst:125797"/>
            <criterion comment="control-center-devel is earlier than 0:2.28.1-39.el6" test_ref="oval:org.mitre.oval:tst:126059"/>
            <criterion comment="control-center-extra is earlier than 0:2.28.1-39.el6" test_ref="oval:org.mitre.oval:tst:125994"/>
            <criterion comment="control-center-filesystem is earlier than 0:2.28.1-39.el6" test_ref="oval:org.mitre.oval:tst:126108"/>
            <criterion comment="ekiga is earlier than 0:3.2.6-4.el6" test_ref="oval:org.mitre.oval:tst:125539"/>
            <criterion comment="evolution is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:125975"/>
            <criterion comment="evolution-data-server is earlier than 0:2.32.3-18.el6" test_ref="oval:org.mitre.oval:tst:125677"/>
            <criterion comment="evolution-data-server-devel is earlier than 0:2.32.3-18.el6" test_ref="oval:org.mitre.oval:tst:125610"/>
            <criterion comment="evolution-data-server-doc is earlier than 0:2.32.3-18.el6" test_ref="oval:org.mitre.oval:tst:126010"/>
            <criterion comment="evolution-devel is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:125967"/>
            <criterion comment="evolution-devel-docs is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:126018"/>
            <criterion comment="evolution-exchange is earlier than 0:2.32.3-16.el6" test_ref="oval:org.mitre.oval:tst:126073"/>
            <criterion comment="evolution-help is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:125686"/>
            <criterion comment="evolution-mapi is earlier than 0:0.32.2-12.el6" test_ref="oval:org.mitre.oval:tst:126050"/>
            <criterion comment="evolution-mapi-devel is earlier than 0:0.32.2-12.el6" test_ref="oval:org.mitre.oval:tst:126063"/>
            <criterion comment="evolution-perl is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:125759"/>
            <criterion comment="evolution-pst is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:125553"/>
            <criterion comment="evolution-spamassassin is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:125909"/>
            <criterion comment="finch is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:125908"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:125757"/>
            <criterion comment="gnome-panel is earlier than 0:2.30.2-15.el6" test_ref="oval:org.mitre.oval:tst:125282"/>
            <criterion comment="gnome-panel-devel is earlier than 0:2.30.2-15.el6" test_ref="oval:org.mitre.oval:tst:126044"/>
            <criterion comment="gnome-panel-libs is earlier than 0:2.30.2-15.el6" test_ref="oval:org.mitre.oval:tst:125346"/>
            <criterion comment="gnome-python2-applet is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125712"/>
            <criterion comment="gnome-python2-brasero is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:126049"/>
            <criterion comment="gnome-python2-bugbuddy is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125625"/>
            <criterion comment="gnome-python2-desktop is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125743"/>
            <criterion comment="gnome-python2-evince is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125752"/>
            <criterion comment="gnome-python2-evolution is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125850"/>
            <criterion comment="gnome-python2-gnomedesktop is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125785"/>
            <criterion comment="gnome-python2-gnomekeyring is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125298"/>
            <criterion comment="gnome-python2-gnomeprint is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125935"/>
            <criterion comment="gnome-python2-gtksourceview is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125554"/>
            <criterion comment="gnome-python2-libgtop2 is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:126069"/>
            <criterion comment="gnome-python2-libwnck is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125865"/>
            <criterion comment="gnome-python2-metacity is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125599"/>
            <criterion comment="gnome-python2-rsvg is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125939"/>
            <criterion comment="gnome-python2-totem is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125997"/>
            <criterion comment="gtkhtml3 is earlier than 0:3.32.2-2.el6" test_ref="oval:org.mitre.oval:tst:125992"/>
            <criterion comment="gtkhtml3-devel is earlier than 0:3.32.2-2.el6" test_ref="oval:org.mitre.oval:tst:125720"/>
            <criterion comment="libgdata is earlier than 0:0.6.4-2.el6" test_ref="oval:org.mitre.oval:tst:125273"/>
            <criterion comment="libgdata-devel is earlier than 0:0.6.4-2.el6" test_ref="oval:org.mitre.oval:tst:125978"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:125915"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:125332"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:125861"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:125509"/>
            <criterion comment="nautilus-sendto is earlier than 0:2.28.2-4.el6" test_ref="oval:org.mitre.oval:tst:125889"/>
            <criterion comment="nautilus-sendto-devel is earlier than 0:2.28.2-4.el6" test_ref="oval:org.mitre.oval:tst:125572"/>
            <criterion comment="openchange is earlier than 0:1.0-6.el6" test_ref="oval:org.mitre.oval:tst:125835"/>
            <criterion comment="openchange-client is earlier than 0:1.0-6.el6" test_ref="oval:org.mitre.oval:tst:125816"/>
            <criterion comment="openchange-devel is earlier than 0:1.0-6.el6" test_ref="oval:org.mitre.oval:tst:125896"/>
            <criterion comment="openchange-devel-docs is earlier than 0:1.0-6.el6" test_ref="oval:org.mitre.oval:tst:125393"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:126030"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:125957"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:126035"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:125789"/>
            <criterion comment="planner is earlier than 0:0.14.4-10.el6" test_ref="oval:org.mitre.oval:tst:125969"/>
            <criterion comment="planner-devel is earlier than 0:0.14.4-10.el6" test_ref="oval:org.mitre.oval:tst:125584"/>
            <criterion comment="planner-eds is earlier than 0:0.14.4-10.el6" test_ref="oval:org.mitre.oval:tst:126075"/>
            <criterion comment="totem is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:125638"/>
            <criterion comment="totem-devel is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:125932"/>
            <criterion comment="totem-jamendo is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:125949"/>
            <criterion comment="totem-mozplugin is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:126054"/>
            <criterion comment="totem-nautilus is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:125972"/>
            <criterion comment="totem-upnp is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:125611"/>
            <criterion comment="totem-youtube is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:125890"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cheese-debuginfo is earlier than 0:2.28.1-8.el6" test_ref="oval:org.mitre.oval:tst:125710"/>
            <criterion comment="control-center-debuginfo is earlier than 0:2.28.1-39.el6" test_ref="oval:org.mitre.oval:tst:126003"/>
            <criterion comment="ekiga-debuginfo is earlier than 0:3.2.6-4.el6" test_ref="oval:org.mitre.oval:tst:125619"/>
            <criterion comment="evolution-data-server-debuginfo is earlier than 0:2.32.3-18.el6" test_ref="oval:org.mitre.oval:tst:126085"/>
            <criterion comment="evolution-debuginfo is earlier than 0:2.32.3-30.el6" test_ref="oval:org.mitre.oval:tst:125845"/>
            <criterion comment="evolution-exchange-debuginfo is earlier than 0:2.32.3-16.el6" test_ref="oval:org.mitre.oval:tst:126014"/>
            <criterion comment="evolution-mapi-debuginfo is earlier than 0:0.32.2-12.el6" test_ref="oval:org.mitre.oval:tst:125188"/>
            <criterion comment="gnome-panel-debuginfo is earlier than 0:2.30.2-15.el6" test_ref="oval:org.mitre.oval:tst:126104"/>
            <criterion comment="gnome-python2-desktop-debuginfo is earlier than 0:2.28.0-5.el6" test_ref="oval:org.mitre.oval:tst:125794"/>
            <criterion comment="gtkhtml3-debuginfo is earlier than 0:3.32.2-2.el6" test_ref="oval:org.mitre.oval:tst:125960"/>
            <criterion comment="libgdata-debuginfo is earlier than 0:0.6.4-2.el6" test_ref="oval:org.mitre.oval:tst:125445"/>
            <criterion comment="nautilus-sendto-debuginfo is earlier than 0:2.28.2-4.el6" test_ref="oval:org.mitre.oval:tst:125375"/>
            <criterion comment="openchange-debuginfo is earlier than 0:1.0-6.el6" test_ref="oval:org.mitre.oval:tst:125400"/>
            <criterion comment="pidgin-debuginfo is earlier than 0:2.7.9-11.el6" test_ref="oval:org.mitre.oval:tst:125996"/>
            <criterion comment="planner-debuginfo is earlier than 0:0.14.4-10.el6" test_ref="oval:org.mitre.oval:tst:125706"/>
            <criterion comment="totem-debuginfo is earlier than 0:2.28.6-4.el6" test_ref="oval:org.mitre.oval:tst:125238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27101" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1606: file security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>file</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1606-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1606.html"/>
        <reference source="CVE" ref_id="CVE-2012-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1571.html"/>
        <reference source="CVE" ref_id="CVE-2014-0237" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0237.html"/>
        <reference source="CVE" ref_id="CVE-2014-0238" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0238.html"/>
        <reference source="CVE" ref_id="CVE-2014-1943" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1943.html"/>
        <reference source="CVE" ref_id="CVE-2014-2270" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2270.html"/>
        <reference source="CVE" ref_id="CVE-2014-3479" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3479.html"/>
        <reference source="CVE" ref_id="CVE-2014-3480" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3480.html"/>
        <reference source="CESA-2014:1606" ref_id="CESA-2014:1606" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001176.html"/>
        <description>The "file" command is used to identify a particular file according to the
type of data contained in the file. The command can identify various file
types, including ELF binaries, system libraries, RPM packages, and
different graphics formats.

Multiple denial of service flaws were found in the way file parsed certain
Composite Document Format (CDF) files. A remote attacker could use either
of these flaws to crash file, or an application using file, via a specially
crafted CDF file. (CVE-2014-0237, CVE-2014-0238, CVE-2014-3479,
CVE-2014-3480, CVE-2012-1571)

Two denial of service flaws were found in the way file handled indirect and
search rules. A remote attacker could use either of these flaws to cause
file, or an application using file, to crash or consume an excessive amount
of CPU. (CVE-2014-1943, CVE-2014-2270)

This update also fixes the following bugs:

* Previously, the output of the "file" command contained redundant white
spaces. With this update, the new STRING_TRIM flag has been introduced to
remove the unnecessary white spaces. (BZ#664513)

* Due to a bug, the "file" command could incorrectly identify an XML
document as a LaTex document. The underlying source code has been modified
to fix this bug and the command now works as expected. (BZ#849621)

* Previously, the "file" command could not recognize .JPG files and
incorrectly labeled them as "Minix filesystem". This bug has been fixed and
the command now properly detects .JPG files. (BZ#873997)

* Under certain circumstances, the "file" command incorrectly detected
NETpbm files as "x86 boot sector". This update applies a patch to fix this
bug and the command now detects NETpbm files as expected. (BZ#884396)

* Previously, the "file" command incorrectly identified ASCII text files as
a .PIC image file. With this update, a patch has been provided to address
this bug and the command now correctly recognizes ASCII text files.
(BZ#980941)

* On 32-bit PowerPC systems, the "from" field was missing from the output
of the "file" command. The underlying source code has been modified to fix
this bug and "file" output now contains the "from" field as expected.
(BZ#1037279)

* The "file" command incorrectly detected text files as "RRDTool DB version
ool - Round Robin Database Tool". This update applies a patch to fix this
bug and the command now correctly detects text files. (BZ#1064463)

* Previously, the "file" command supported only version 1 and 2 of the QCOW
format. As a consequence, file was unable to detect a "qcow2 compat=1.1"
file created on Red Hat Enterprise Linux 7. With this update, support for
QCOW version 3 has been added so that the command now detects such files as
expected. (BZ#1067771)

All file users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:27.593-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:37.679-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:14.357-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27101 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:55.005-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:14.895-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="file is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:125002"/>
            <criterion comment="file-devel is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:125284"/>
            <criterion comment="file-libs is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:125016"/>
            <criterion comment="file-static is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:125271"/>
            <criterion comment="python-magic is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:125014"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="file-debuginfo is earlier than 0:5.04-21.el6" test_ref="oval:org.mitre.oval:tst:137596"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27087" version="5" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: RHSA-2013:1591 -- openssh security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1591.html" ref_id="RHSA-2013:1591"/>
        <reference source="CESA-2013:1591" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/001033.html" ref_id="CESA-2013:1591"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5107" ref_id="CVE-2010-5107"/>
        <description>OpenSSH is OpenBSD&amp;#39;s Secure Shell (SSH) protocol implementation.
These packages include the core files necessary for the OpenSSH client
and server.

The default OpenSSH configuration made it easy for remote attackers to
exhaust unauthorized connection slots and prevent other users from being
able to log in to a system. This flaw has been addressed by enabling random
early connection drops by setting MaxStartups to 10:30:100 by default.
For more information, refer to the sshd_config(5) man page. (CVE-2010-5107)

These updated openssh packages include numerous bug fixes and enhancements.
Space precludes documenting all of these changes in this advisory.
Users are directed to the Red Hat Enterprise Linux 6.5 Technical Notes,
linked to in the References, for information on the most significant of
these changes.

All openssh users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add
these enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:15:56">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:09.143-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:42.785-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:36.058-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:42383 - Updated States &amp; Objects" date="2015-02-02T15:56:00.526-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-02T16:00:51.489-05:00">INTERIM</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-11T18:32:22.009-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T18:32:22.009-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="openssh-debuginfo is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:125742"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssh is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:126082"/>
            <criterion comment="openssh-askpass is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:126150"/>
            <criterion comment="openssh-clients is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:126169"/>
            <criterion comment="openssh-ldap is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:125504"/>
            <criterion comment="openssh-server is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:125500"/>
            <criterion comment="pam_ssh_agent_auth is earlier than 0:0.9.3-94.el6" test_ref="oval:org.mitre.oval:tst:126151"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27086" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1392: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1392-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1392.html"/>
        <reference source="CVE" ref_id="CVE-2013-2596" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2596.html"/>
        <reference source="CVE" ref_id="CVE-2013-4483" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4483.html"/>
        <reference source="CVE" ref_id="CVE-2014-0181" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0181.html"/>
        <reference source="CVE" ref_id="CVE-2014-3122" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3122.html"/>
        <reference source="CVE" ref_id="CVE-2014-3601" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3601.html"/>
        <reference source="CVE" ref_id="CVE-2014-4608" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4608.html"/>
        <reference source="CVE" ref_id="CVE-2014-4653" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4653.html"/>
        <reference source="CVE" ref_id="CVE-2014-4654" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4654.html"/>
        <reference source="CVE" ref_id="CVE-2014-4655" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4655.html"/>
        <reference source="CVE" ref_id="CVE-2014-5045" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-5045.html"/>
        <reference source="CVE" ref_id="CVE-2014-5077" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-5077.html"/>
        <reference source="CESA-2014:1392" ref_id="CESA-2014:1392" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001221.html"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A NULL pointer dereference flaw was found in the way the Linux kernel's
Stream Control Transmission Protocol (SCTP) implementation handled
simultaneous connections between the same hosts. A remote attacker could
use this flaw to crash the system. (CVE-2014-5077, Important)

* An integer overflow flaw was found in the way the Linux kernel's Frame
Buffer device implementation mapped kernel memory to user space via the
mmap syscall. A local user able to access a frame buffer device file
(/dev/fb*) could possibly use this flaw to escalate their privileges on the
system. (CVE-2013-2596, Important)

* A flaw was found in the way the ipc_rcu_putref() function in the Linux
kernel's IPC implementation handled reference counter decrementing.
A local, unprivileged user could use this flaw to trigger an Out of Memory
(OOM) condition and, potentially, crash the system. (CVE-2013-4483,
Moderate)

* It was found that the permission checks performed by the Linux kernel
when a netlink message was received were not sufficient. A local,
unprivileged user could potentially bypass these restrictions by passing a
netlink socket as stdout or stderr to a more privileged process and
altering the output of this process. (CVE-2014-0181, Moderate)

* It was found that the try_to_unmap_cluster() function in the Linux
kernel's Memory Managment subsystem did not properly handle page locking in
certain cases, which could potentially trigger the BUG_ON() macro in the
mlock_vma_page() function. A local, unprivileged user could use this flaw
to crash the system. (CVE-2014-3122, Moderate)

* A flaw was found in the way the Linux kernel's kvm_iommu_map_pages()
function handled IOMMU mapping failures. A privileged user in a guest with
an assigned host device could use this flaw to crash the host.
(CVE-2014-3601, Moderate)

* Multiple use-after-free flaws were found in the way the Linux kernel's
Advanced Linux Sound Architecture (ALSA) implementation handled user
controls. A local, privileged user could use either of these flaws to crash
the system. (CVE-2014-4653, CVE-2014-4654, CVE-2014-4655, Moderate)

* A flaw was found in the way the Linux kernel's VFS subsystem handled
reference counting when performing unmount operations on symbolic links.
A local, unprivileged user could use this flaw to exhaust all available
memory on the system or, potentially, trigger a use-after-free error,
resulting in a system crash or privilege escalation. (CVE-2014-5045,
Moderate)

* An integer overflow flaw was found in the way the lzo1x_decompress_safe()
function of the Linux kernel's LZO implementation processed Literal Runs.
A local attacker could, in extremely rare cases, use this flaw to crash the
system or, potentially, escalate their privileges on the system.
(CVE-2014-4608, Low)

Red Hat would like to thank Vladimir Davydov of Parallels for reporting
CVE-2013-4483, Jack Morgenstein of Mellanox for reporting CVE-2014-3601,
Vasily Averin of Parallels for reporting CVE-2014-5045, and Don A.
Bailey from Lab Mouse Security for reporting CVE-2014-4608. The security
impact of the CVE-2014-3601 issue was discovered by Michael Tsirkin of
Red Hat.

This update also fixes several hundred bugs and adds numerous enhancements.
Refer to the Red Hat Enterprise Linux 6.6 Release Notes for information on
the most significant of these changes, and the Technical Notes for further
information, both linked to in the References.

All Red Hat Enterprise Linux 6 users are advised to install these updated
packages, which correct these issues, and fix the bugs and add the
enhancements noted in the Red Hat Enterprise Linux 6.6 Release Notes and
Technical Notes. The system must be rebooted for this update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:34.790-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:36.556-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:09.944-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27086 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:56.003-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:14.374-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:125082"/>
            <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:125303"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:125193"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:124490"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:125125"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:125087"/>
            <criterion comment="kernel-firmware is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:125201"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:125192"/>
            <criterion comment="perf is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:124896"/>
            <criterion comment="python-perf is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:124312"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-debug-debuginfo is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:137928"/>
            <criterion comment="kernel-debuginfo is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:138123"/>
            <criterion comment="kernel-debuginfo-common-i686 is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:138328"/>
            <criterion comment="perf-debuginfo is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:138095"/>
            <criterion comment="python-perf-debuginfo is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:138041"/>
            <criterion comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-504.el6" test_ref="oval:org.mitre.oval:tst:138390"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27070" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:0519 -- openssh security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0519.html" ref_id="RHSA-2013:0519"/>
        <reference source="CESA-2013:0519" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-February/000649.html" ref_id="CESA-2013:0519"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5536" ref_id="CVE-2012-5536"/>
        <description><![CDATA[OpenSSH is OpenBSD&#39;s Secure Shell (SSH) protocol implementation. These
packages include the core files necessary for the OpenSSH client and
server.

Due to the way the pam_ssh_agent_auth PAM module was built in Red Hat
Enterprise Linux 6, the glibc&#39;s error() function was called rather than the
intended error() function in pam_ssh_agent_auth to report errors. As these
two functions expect different arguments, it was possible for an attacker
to cause an application using pam_ssh_agent_auth to crash, disclose
portions of its memory or, potentially, execute arbitrary code.
(CVE-2012-5536)

Note that the pam_ssh_agent_auth module is not used in Red Hat Enterprise
Linux 6 by default.

This update also fixes the following bugs:

* All possible options for the new RequiredAuthentications directive were
not documented in the sshd_config man page. This update improves the man
page to document all the possible options. (BZ#821641)

* When stopping one instance of the SSH daemon (sshd), the sshd init script
(/etc/rc.d/init.d/sshd) stopped all sshd processes regardless of the PID of
the processes. This update improves the init script so that it only kills
processes with the relevant PID. As a result, the init script now works
more reliably in a multi-instance environment. (BZ#826720)

* Due to a regression, the ssh-copy-id command returned an exit status code
of zero even if there was an error in copying the key to a remote host.
With this update, a patch has been applied and ssh-copy-id now returns a
non-zero exit code if there is an error in copying the SSH certificate to a
remote host. (BZ#836650)

* When SELinux was disabled on the system, no on-disk policy was installed,
a user account was used for a connection, and no &quot;~/.ssh&quot; configuration was
present in that user&#39;s home directory, the SSH client terminated
unexpectedly with a segmentation fault when attempting to connect to
another system. A patch has been provided to address this issue and the
crashes no longer occur in the described scenario. (BZ#836655)

* The &quot;HOWTO&quot; document /usr/share/doc/openssh-ldap-5.3p1/HOWTO.ldap-keys
incorrectly documented the use of the AuthorizedKeysCommand directive.
This update corrects the document. (BZ#857760)

This update also adds the following enhancements:

* When attempting to enable SSH for use with a Common Access Card (CAC),
the ssh-agent utility read all the certificates in the card even though
only the ID certificate was needed. Consequently, if a user entered their
PIN incorrectly, then the CAC was locked, as a match for the PIN was
attempted against all three certificates. With this update, ssh-add does
not try the same PIN for every certificate if the PIN fails for the first
one. As a result, the CAC will not be disabled if a user enters their PIN
incorrectly. (BZ#782912)

* This update adds a &quot;netcat mode&quot; to SSH. The &quot;ssh -W host:port ...&quot;
command connects standard input and output (stdio) on a client to a single
port on a server. As a result, SSH can be used to route connections via
intermediate servers. (BZ#860809)

* Due to a bug, arguments for the RequiredAuthentications2 directive were
not stored in a Match block. Consequently, parsing of the config file was
not in accordance with the man sshd_config documentation. This update fixes
the bug and users can now use the required authentication feature to
specify a list of authentication methods as expected according to the man
page. (BZ#869903)

All users of openssh are advised to upgrade to these updated packages,
which fix these issues and add these enhancements. After installing this
update, the OpenSSH server daemon (sshd) will be restarted automatically.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:04">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:36.814-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:41.072-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:35.124-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:42383 - Updated States &amp; Objects" date="2015-02-02T15:56:00.526-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-02T16:00:51.384-05:00">INTERIM</status_change>
            <status_change date="2015-02-23T04:00:53.473-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="openssh-debuginfo is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:125987"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssh is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:125479"/>
            <criterion comment="openssh-askpass is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:126146"/>
            <criterion comment="openssh-clients is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:126032"/>
            <criterion comment="openssh-ldap is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:125331"/>
            <criterion comment="openssh-server is earlier than 0:5.3p1-84.1.el6" test_ref="oval:org.mitre.oval:tst:126182"/>
            <criterion comment="pam_ssh_agent_auth is earlier than 0:0.9.3-84.1.el6" test_ref="oval:org.mitre.oval:tst:126124"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27068" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1658: java-1.6.0-sun security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1658-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1658.html"/>
        <reference source="CVE" ref_id="CVE-2014-4288" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4288.html"/>
        <reference source="CVE" ref_id="CVE-2014-6457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6457.html"/>
        <reference source="CVE" ref_id="CVE-2014-6458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6458.html"/>
        <reference source="CVE" ref_id="CVE-2014-6492" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6492.html"/>
        <reference source="CVE" ref_id="CVE-2014-6493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6493.html"/>
        <reference source="CVE" ref_id="CVE-2014-6502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6502.html"/>
        <reference source="CVE" ref_id="CVE-2014-6503" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6503.html"/>
        <reference source="CVE" ref_id="CVE-2014-6504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6504.html"/>
        <reference source="CVE" ref_id="CVE-2014-6506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6506.html"/>
        <reference source="CVE" ref_id="CVE-2014-6511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6511.html"/>
        <reference source="CVE" ref_id="CVE-2014-6512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6512.html"/>
        <reference source="CVE" ref_id="CVE-2014-6515" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6515.html"/>
        <reference source="CVE" ref_id="CVE-2014-6517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6517.html"/>
        <reference source="CVE" ref_id="CVE-2014-6531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6531.html"/>
        <reference source="CVE" ref_id="CVE-2014-6532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6532.html"/>
        <reference source="CVE" ref_id="CVE-2014-6558" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6558.html"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-4288, CVE-2014-6457, CVE-2014-6458, CVE-2014-6492, CVE-2014-6493,
CVE-2014-6502, CVE-2014-6503, CVE-2014-6504, CVE-2014-6506, CVE-2014-6511,
CVE-2014-6512, CVE-2014-6515, CVE-2014-6517, CVE-2014-6531, CVE-2014-6532,
CVE-2014-6558)

The CVE-2014-6512 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 85 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:29.178-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:34.610-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:02:00.627-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27068 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:41.881-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:47.238-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:141202"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:140933"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:141151"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:141228"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:140660"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.3.el5_11" test_ref="oval:org.mitre.oval:tst:140941"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125078"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125319"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125276"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125088"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125249"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125368"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:140874"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141147"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141206"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141137"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141080"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:140292"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27062" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0255 -- subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0255.html" ref_id="RHSA-2014:0255"/>
        <reference source="CESA-2014:0255" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-March/020189.html" ref_id="CESA-2014:0255"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1968" ref_id="CVE-2013-1968"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2112" ref_id="CVE-2013-2112"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0032" ref_id="CVE-2014-0032"/>
        <description>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes. The
mod_dav_svn module is used with the Apache HTTP Server to allow access to
Subversion repositories via HTTP.

A flaw was found in the way the mod_dav_svn module handled OPTIONS
requests. A remote attacker with read access to an SVN repository served
via HTTP could use this flaw to cause the httpd process that handled such a
request to crash. (CVE-2014-0032)

A flaw was found in the way Subversion handled file names with newline
characters when the FSFS repository format was used. An attacker with
commit access to an SVN repository could corrupt a revision by committing a
specially crafted file. (CVE-2013-1968)

A flaw was found in the way the svnserve tool of Subversion handled remote
client network connections. An attacker with read access to an SVN
repository served via svnserve could use this flaw to cause the svnserve
daemon to exit, leading to a denial of service. (CVE-2013-2112)

All subversion users should upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, for the update to take effect, you must restart the httpd
daemon, if you are using mod_dav_svn, and the svnserve daemon, if you are
serving Subversion repositories via the svn:// protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:35">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:56.701-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:38.486-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:34.769-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:125411"/>
            <criterion comment="subversion is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:125048"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:126009"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:125958"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:126006"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:125062"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="subversion-debuginfo is earlier than 0:1.6.11-12.el5_10" test_ref="oval:org.mitre.oval:tst:126061"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125681"/>
            <criterion comment="subversion is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:126034"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125974"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125069"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125508"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:126051"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:126055"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125809"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125525"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="subversion-debuginfo is earlier than 0:1.6.11-10.el6_5" test_ref="oval:org.mitre.oval:tst:125964"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27056" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1388: cups security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1388-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1388.html"/>
        <reference source="CVE" ref_id="CVE-2014-2856" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2856.html"/>
        <reference source="CVE" ref_id="CVE-2014-3537" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3537.html"/>
        <reference source="CVE" ref_id="CVE-2014-5029" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-5029.html"/>
        <reference source="CVE" ref_id="CVE-2014-5030" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-5030.html"/>
        <reference source="CVE" ref_id="CVE-2014-5031" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-5031.html"/>
        <reference source="CESA-2014:1388" ref_id="CESA-2014:1388" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001160.html"/>
        <description>CUPS provides a portable printing layer for Linux, UNIX, and similar
operating systems.

A cross-site scripting (XSS) flaw was found in the CUPS web interface.
An attacker could use this flaw to perform a cross-site scripting attack
against users of the CUPS web interface. (CVE-2014-2856)

It was discovered that CUPS allowed certain users to create symbolic links
in certain directories under /var/cache/cups/. A local user with the 'lp'
group privileges could use this flaw to read the contents of arbitrary
files on the system or, potentially, escalate their privileges on the
system. (CVE-2014-3537, CVE-2014-5029, CVE-2014-5030, CVE-2014-5031)

The CVE-2014-3537 issue was discovered by Francisco Alonso of Red Hat
Product Security.

These updated cups packages also include several bug fixes. Space precludes
documenting all of these changes in this advisory. Users are directed to
the Red Hat Enterprise Linux 6.6 Technical Notes, linked to in the
References section, for information on the most significant of these
changes.

All cups users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the cupsd daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:30.545-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:34.222-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:58.775-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:27056 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:50.416-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:14.060-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cups is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:124470"/>
            <criterion comment="cups-devel is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:125208"/>
            <criterion comment="cups-libs is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:124980"/>
            <criterion comment="cups-lpd is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:125225"/>
            <criterion comment="cups-php is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:124607"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="cups-debuginfo is earlier than 1:1.4.2-67.el6" test_ref="oval:org.mitre.oval:tst:138122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27049" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1620 -- xorg-x11-server security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1620.html" ref_id="RHSA-2013:1620"/>
        <reference source="CESA-2013:1620" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/001120.html" ref_id="CESA-2013:1620"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1940" ref_id="CVE-2013-1940"/>
        <description>X.Org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

A flaw was found in the way the X.org X11 server registered new hot plugged
devices. If a local user switched to a different session and plugged in a
new device, input from that device could become available in the previous
session, possibly leading to information disclosure. (CVE-2013-1940)

This issue was found by David Airlie and Peter Hutterer of Red Hat.

This update also fixes the following bugs:

* A previous upstream patch modified the Xephyr X server to be resizeable,
however, it did not enable the resize functionality by default. As a
consequence, X sandboxes were not resizeable on Red Hat Enterprise Linux
6.4 and later. This update enables the resize functionality by default so
that X sandboxes can now be resized as expected. (BZ#915202)

* In Red Hat Enterprise Linux 6, the X Security extension (XC-SECURITY)
has been disabled and replaced by X Access Control Extension (XACE).
However, XACE does not yet include functionality that was previously
available in XC-SECURITY. With this update, XC-SECURITY is enabled in the
xorg-x11-server spec file on Red Hat Enterprise Linux 6. (BZ#957298)

* Upstream code changes to extension initialization accidentally disabled
the GLX extension in Xvfb (the X virtual frame buffer), rendering headless
3D applications not functional. An upstream patch to this problem has been
backported so the GLX extension is enabled again, and applications relying
on this extension work as expected. (BZ#969538)

All xorg-x11-server users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:15:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:06.489-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:36.734-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:34.281-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:125853"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:125863"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:125895"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:125475"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:125180"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:125187"/>
            <criterion comment="xorg-x11-server-debuginfo is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:125954"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:125802"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.el6" test_ref="oval:org.mitre.oval:tst:126111"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.el6.centos" test_ref="oval:org.mitre.oval:tst:125869"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.el6.centos" test_ref="oval:org.mitre.oval:tst:125687"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.el6.centos" test_ref="oval:org.mitre.oval:tst:126128"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.el6.centos" test_ref="oval:org.mitre.oval:tst:126078"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.el6.centos" test_ref="oval:org.mitre.oval:tst:126113"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.el6.centos" test_ref="oval:org.mitre.oval:tst:125672"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.el6.centos" test_ref="oval:org.mitre.oval:tst:126166"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.el6.centos" test_ref="oval:org.mitre.oval:tst:126178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27046" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1635 -- cups security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1635.html" ref_id="RHSA-2011:1635"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2896" ref_id="CVE-2011-2896"/>
        <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

A heap-based buffer overflow flaw was found in the Lempel-Ziv-Welch (LZW)
decompression algorithm implementation used by the CUPS GIF image format
reader. An attacker could create a malicious GIF image file that, when
printed, could possibly cause CUPS to crash or, potentially, execute
arbitrary code with the privileges of the &amp;quot;lp&amp;quot; user. (CVE-2011-2896)

These updated cups packages also provide fixes for the following bugs:

* Previously CUPS was not correctly handling the language setting
LANG=en_US.ASCII. As a consequence lpadmin, lpstat and lpinfo binaries were
not displaying any output when the LANG=en_US.ASCII environment variable
was used. As a result of this update the problem is fixed and the expected
output is now displayed. (BZ#681836)

* Previously the scheduler did not check for empty values of several
configuration directives. As a consequence it was possible for the CUPS
daemon (cupsd) to crash when a configuration file contained certain empty
values. With this update the problem is fixed and cupsd no longer crashes
when reading such a configuration file. (BZ#706673)

* Previously when printing to a raw print queue, when using certain printer
models, CUPS was incorrectly sending SNMP queries. As a consequence there
was a noticeable 4-second delay between queueing the job and the start of
printing. With this update the problem is fixed and CUPS no longer tries to
collect SNMP supply and status information for raw print queues.
(BZ#709896)

* Previously when using the BrowsePoll directive it could happen that the
CUPS printer polling daemon (cups-polld) began polling before the network
interfaces were set up after a system boot. CUPS was then caching the
failed hostname lookup. As a consequence no printers were found and the
error, &amp;quot;Host name lookup failure&amp;quot;, was logged. With this update the code
that re-initializes the resolver after failure in cups-polld is fixed and
as a result CUPS will obtain the correct network settings to use in printer
discovery. (BZ#712430)

* The MaxJobs directive controls the maximum number of print jobs that are
kept in memory. Previously, once the number of jobs reached the limit, the
CUPS system failed to automatically purge the data file associated with the
oldest completed job from the system in order to make room for a new print
job. This bug has been fixed, and the jobs beyond the set limit are now
properly purged. (BZ#735505)

* The cups init script (/etc/rc.d/init.d/cups) uses the daemon function
(from /etc/rc.d/init.d/functions) to start the cups process, but previously
it did not source a configuration file from the /etc/sysconfig/ directory.
As a consequence, it was difficult to cleanly set the nice level or cgroup
for the cups daemon by setting the NICELEVEL or CGROUP_DAEMON variables.
With this update, the init script is fixed. (BZ#744791)

All users of CUPS are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing this
update, the cupsd daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:45.517-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:36.491-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:34.096-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="cups is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:126210"/>
          <criterion comment="cups-debuginfo is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:125433"/>
          <criterion comment="cups-devel is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:126195"/>
          <criterion comment="cups-libs is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:125345"/>
          <criterion comment="cups-lpd is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:125495"/>
          <criterion comment="cups-php is earlier than 0:1.4.2-44.el6" test_ref="oval:org.mitre.oval:tst:126307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27044" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1615 -- php security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1615.html" ref_id="RHSA-2013:1615"/>
        <reference source="CESA-2013:1615" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/001046.html" ref_id="CESA-2013:1615"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-7243" ref_id="CVE-2006-7243"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1643" ref_id="CVE-2013-1643"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4248" ref_id="CVE-2013-4248"/>
        <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server.

It was found that PHP did not properly handle file names with a NULL
character. A remote attacker could possibly use this flaw to make a PHP
script access unexpected files and bypass intended file system access
restrictions. (CVE-2006-7243)

A flaw was found in PHP&amp;#39;s SSL client&amp;#39;s hostname identity check when
handling certificates that contain hostnames with NULL bytes. If an
attacker was able to get a carefully crafted certificate signed by a
trusted Certificate Authority, the attacker could use the certificate to
conduct man-in-the-middle attacks to spoof SSL servers. (CVE-2013-4248)

It was found that the PHP SOAP parser allowed the expansion of external XML
entities during SOAP message parsing. A remote attacker could possibly use
this flaw to read arbitrary files that are accessible to a PHP application
using a SOAP extension. (CVE-2013-1643)

This update fixes the following bugs:

* Previously, when the allow_call_time_pass_reference setting was disabled,
a virtual host on the Apache server could terminate with a segmentation
fault when attempting to process certain PHP content. This bug has been
fixed and virtual hosts no longer crash when allow_call_time_pass_reference
is off. (BZ#892158, BZ#910466)

* Prior to this update, if an error occurred during the operation of the
fclose(), file_put_contents(), or copy() function, the function did not
report it. This could have led to data loss. With this update, the
aforementioned functions have been modified to properly report any errors.
(BZ#947429)

* The internal buffer for the SQLSTATE error code can store maximum of 5
characters. Previously, when certain calls exceeded this limit, a buffer
overflow occurred. With this update, messages longer than 5 characters are
automatically replaced with the default &amp;quot;HY000&amp;quot; string, thus preventing the
overflow. (BZ#969110)

In addition, this update adds the following enhancement:

* This update adds the following rpm macros to the php package: %__php,
%php_inidir, %php_incldir. (BZ#953814)

Users of php are advised to upgrade to these updated packages, which fix
these bugs and add this enhancement. After installing the updated packages,
the httpd daemon must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:15:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:38.932-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:35.934-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:33.699-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="php is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125573"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125732"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125791"/>
            <criterion comment="php-common is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125408"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125936"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:126017"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125913"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125956"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125729"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125971"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125963"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:126093"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:126088"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:126066"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125899"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125841"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125630"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:126132"/>
            <criterion comment="php-process is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125148"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125541"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:126143"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:126094"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125576"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125595"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125980"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125153"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:125986"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="php-debuginfo is earlier than 0:5.3.3-26.el6" test_ref="oval:org.mitre.oval:tst:126090"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27008" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1691 -- util-linux-ng security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>util-linux-ng</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1691.html" ref_id="RHSA-2011:1691"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1675" ref_id="CVE-2011-1675"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1677" ref_id="CVE-2011-1677"/>
        <description><![CDATA[The util-linux-ng packages contain a large variety of low-level system
utilities that are necessary for a Linux operating system to function.

Multiple flaws were found in the way the mount and umount commands
performed mtab (mounted file systems table) file updates. A local,
unprivileged user allowed to mount or unmount file systems could use these
flaws to corrupt the mtab file and create a stale lock file, preventing
other users from mounting and unmounting file systems. (CVE-2011-1675,
CVE-2011-1677)

This update also fixes the following bugs:

* Due to a hard coded limit of 128 devices, an attempt to run the
&quot;blkid -c&quot; command on more than 128 devices caused blkid to terminate
unexpectedly. This update increases the maximum number of devices to 8192
so that blkid no longer crashes in this scenario. (BZ#675999)

* Previously, the &quot;swapon -a&quot; command did not detect device-mapper
devices that were already in use. This update corrects the swapon utility
to detect such devices as expected. (BZ#679741)

* Prior to this update, the presence of an invalid line in the /etc/fstab
file could cause the umount utility to terminate unexpectedly with
a segmentation fault. This update applies a patch that corrects this error
so that umount now correctly reports invalid lines and no longer crashes.
(BZ#684203)

* Previously, an attempt to use the wipefs utility on a partitioned
device caused the utility to terminate unexpectedly with an error. This
update adapts wipefs to only display a warning message in this situation.
(BZ#696959)

* When providing information on interprocess communication (IPC)
facilities, the ipcs utility could previously display a process owner as
a negative number if the user&#39;s UID was too large. This update adapts the
underlying source code to make sure the UID values are now displayed
correctly. (BZ#712158)

* In the installation scriptlets, the uuidd package uses the chkconfig
utility to enable and disable the uuidd service. Previously, this package
did not depend on the chkconfig package, which could lead to errors during
installation if chkconfig was not installed. This update adds chkconfig
to the list of dependencies so that such errors no longer occur.
(BZ#712808)

* The previous version of the /etc/udev/rules.d/60-raw.rules file
contained a statement that both this file and raw devices are deprecated.
This is no longer true and the Red Hat Enterprise Linux kernel supports
this functionality. With this update, the aforementioned file no longer
contains this incorrect statement. (BZ#716995)

* Previously, an attempt to use the cfdisk utility to read the default
Red Hat Enterprise Linux 6 partition layout failed with an error. This
update corrects this error and the cfdisk utility can now read the default
partition layout as expected. (BZ#723352)

* The previous version of the tailf(1) manual page incorrectly stated that
users can use the &quot;--lines=NUMBER&quot; command line option to limit the number
of displayed lines. However, the tailf utility does not allow the use of
the equals sign (=) between the option and its argument. This update
corrects this error. (BZ#679831)

* The fstab(5) manual page has been updated to clarify that empty lines in
the /etc/fstab configuration file are ignored. (BZ#694648)

As well, this update adds the following enhancements:

* A new fstrim utility has been added to the package. This utility allows
the root user to discard unused blocks on a mounted file system.
(BZ#692119)

* The login utility has been updated to provide support for failed login
attempts that are reported by PAM. (BZ#696731)

* The lsblk utility has been updated to provide additional information
about the topology and status of block devices. (BZ#723638)

* The agetty utility has been updated to pass the hostname to the login
utility. (BZ#726092)

All users of util-linux-ng are advised to upgrade to these updated
packages, which contain backported patches to correct these issues and add
these enhancements.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:05.145-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:29.018-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:31.178-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="libblkid is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:126292"/>
          <criterion comment="libblkid-devel is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:126287"/>
          <criterion comment="libuuid is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:125514"/>
          <criterion comment="libuuid-devel is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:126138"/>
          <criterion comment="util-linux-ng is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:126185"/>
          <criterion comment="util-linux-ng-debuginfo is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:125947"/>
          <criterion comment="uuidd is earlier than 0:2.17.2-12.4.el6" test_ref="oval:org.mitre.oval:tst:126346"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27001" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:0520 -- dovecot security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>dovecot</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0520.html" ref_id="RHSA-2013:0520"/>
        <reference source="CESA-2013:0520" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-February/000551.html" ref_id="CESA-2013:0520"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2166" ref_id="CVE-2011-2166"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2167" ref_id="CVE-2011-2167"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4318" ref_id="CVE-2011-4318"/>
        <description>Dovecot is an IMAP server, written with security primarily in mind, for
Linux and other UNIX-like systems. It also contains a small POP3 server. It
supports mail in either of maildir or mbox formats. The SQL drivers and
authentication plug-ins are provided as sub-packages.

Two flaws were found in the way some settings were enforced by the
script-login functionality of Dovecot. A remote, authenticated user could
use these flaws to bypass intended access restrictions or conduct a
directory traversal attack by leveraging login scripts. (CVE-2011-2166,
CVE-2011-2167)

A flaw was found in the way Dovecot performed remote server identity
verification, when it was configured to proxy IMAP and POP3 connections to
remote hosts using TLS/SSL protocols. A remote attacker could use this flaw
to conduct man-in-the-middle attacks using an X.509 certificate issued by
a trusted Certificate Authority (for a different name). (CVE-2011-4318)

This update also fixes the following bug:

* When a new user first accessed their IMAP inbox, Dovecot was, under some
circumstances, unable to change the group ownership of the inbox directory
in the user&amp;#39;s Maildir location to match that of the user&amp;#39;s mail spool
(/var/mail/$USER). This correctly generated an &amp;quot;Internal error occurred&amp;quot;
message. However, with a subsequent attempt to access the inbox, Dovecot
saw that the directory already existed and proceeded with its operation,
leaving the directory with incorrectly set permissions. This update
corrects the underlying permissions setting error. When a new user now
accesses their inbox for the first time, and it is not possible to set
group ownership, Dovecot removes the created directory and generates an
error message instead of keeping the directory with incorrect group
ownership. (BZ#697620)

Users of dovecot are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the dovecot service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:57.595-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:27.557-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:30.719-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dovecot is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:126011"/>
            <criterion comment="dovecot-devel is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:126145"/>
            <criterion comment="dovecot-mysql is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:125926"/>
            <criterion comment="dovecot-pgsql is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:126171"/>
            <criterion comment="dovecot-pigeonhole is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:125880"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="dovecot-debuginfo is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:125970"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26996" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1615 -- virt-v2v security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>virt-v2v</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1615.html" ref_id="RHSA-2011:1615"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1773" ref_id="CVE-2011-1773"/>
        <description><![CDATA[virt-v2v is a tool for converting and importing virtual machines to
libvirt-managed KVM (Kernel-based Virtual Machine), or Red Hat Enterprise
Virtualization.

Using virt-v2v to convert a guest that has a password-protected VNC console
to a KVM guest removed that password protection from the converted guest:
after conversion, a password was not required to access the converted
guest&#39;s VNC console. Now, converted guests will require the same VNC
console password as the original guest. Note that when converting a guest
to run on Red Hat Enterprise Virtualization, virt-v2v will display a
warning that VNC passwords are not supported. (CVE-2011-1773)

Note: The Red Hat Enterprise Linux 6.2 perl-Sys-Virt update must also be
installed to correct CVE-2011-1773.

Bug fixes:

* When converting a guest virtual machine (VM), whose name contained
certain characters, virt-v2v would create a converted guest with a
corrupted name. Now, virt-v2v will not corrupt guest names. (BZ#665883)

* There were numerous usability issues when running virt-v2v as a non-root
user. This update makes it simpler to run virt-v2v as a non-root user.
(BZ#671094)

* virt-v2v failed to convert a Microsoft Windows guest with Windows
Recovery Console installed in a separate partition. Now, virt-v2v will
successfully convert a guest with Windows Recovery Console installed in a
separate partition by ignoring that partition. (BZ#673066)

* virt-v2v failed to convert a Red Hat Enterprise Linux guest which did not
have the symlink &quot;/boot/grub/menu.lst&quot;. With this update, virt-v2v can
select a grub configuration file from several places. (BZ#694364)

* This update removes information about the usage of deprecated command
line options in the virt-v2v man page. (BZ#694370)

* virt-v2v would fail to correctly change the allocation policy, (sparse or
preallocated) when converting a guest with QCOW2 image format. The error
message &quot;Cannot import VM, The selected disk configuration is not
supported&quot; was displayed. With this update, allocation policy changes to a
guest with QCOW2 storage will work correctly. (BZ#696089)

* The options &quot;--network&quot; and &quot;--bridge&quot; can not be used in conjunction
when converting a guest, but no error message was displayed. With this
update, virt-v2v will now display an error message if the mutually
exclusive &quot;--network&quot; and &quot;--bridge&quot; command line options are both
specified. (BZ#700759)

* virt-v2v failed to convert a multi-boot guest, and did not clean up
temporary storage and mount points after failure. With this update,
virt-v2v will prompt for which operating system to convert from a
multi-boot guest, and will correctly clean up if the process fails.
(BZ#702007)

* virt-v2v failed to correctly configure modprobe aliases when converting a
VMware ESX guest with VMware Tools installed. With this update, modprobe
aliases will be correctly configured. (BZ#707261)

* When converting a guest with preallocated raw storage using the
libvirtxml input method, virt-v2v failed with the erroneous error message
&quot;size(X) &lt; usage(Y)&quot;. This update removes this erroneous error. (BZ#727489)

* When converting a Red Hat Enterprise Linux guest, virt-v2v did not check
that the Cirrus X driver was available before configuring it. With this
update, virt-v2v will attempt to install the Cirrus X driver if it is
required. (BZ#708961)

* VirtIO systems do not support the Windows Recovery Console on 32-bit
Windows XP. The virt-v2v man page has been updated to note this. On Windows
XP Professional x64 Edition, however, if Windows Recovery Console is
re-installed after conversion, it will work as expected. (BZ#732421)

* Placing comments in the guest fstab file by means of the leading &quot;#&quot;
symbol caused an &quot;unknown filesystem&quot; error after conversion of a guest.
With this update comments can now be used and error messages will not be
displayed. (BZ#677870)

Users of virt-v2v should upgrade to this updated package, which fixes these
issues and upgrades virt-v2v to version 0.8.3.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:10">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:48.127-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:26.222-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:30.564-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criterion comment="virt-v2v is earlier than 0:0.8.3-5.el6" test_ref="oval:org.mitre.oval:tst:125955"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26947" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1636: java-1.8.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.8.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1636-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1636.html"/>
        <reference source="CVE" ref_id="CVE-2014-6457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6457.html"/>
        <reference source="CVE" ref_id="CVE-2014-6468" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6468.html"/>
        <reference source="CVE" ref_id="CVE-2014-6502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6502.html"/>
        <reference source="CVE" ref_id="CVE-2014-6504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6504.html"/>
        <reference source="CVE" ref_id="CVE-2014-6506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6506.html"/>
        <reference source="CVE" ref_id="CVE-2014-6511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6511.html"/>
        <reference source="CVE" ref_id="CVE-2014-6512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6512.html"/>
        <reference source="CVE" ref_id="CVE-2014-6517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6517.html"/>
        <reference source="CVE" ref_id="CVE-2014-6519" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6519.html"/>
        <reference source="CVE" ref_id="CVE-2014-6531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6531.html"/>
        <reference source="CVE" ref_id="CVE-2014-6558" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6558.html"/>
        <reference source="CVE" ref_id="CVE-2014-6562" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6562.html"/>
        <reference source="CESA-2014:1636" ref_id="CESA-2014:1636" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001471.html"/>
        <description>The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime
Environment and the OpenJDK 8 Java Software Development Kit.

It was discovered that the Libraries component in OpenJDK failed to
properly handle ZIP archives that contain entries with a NUL byte used in
the file names. An untrusted Java application or applet could use this flaw
to bypass Java sandbox restrictions. (CVE-2014-6562)

Multiple flaws were discovered in the Libraries, 2D, and Hotspot components
in OpenJDK. An untrusted Java application or applet could use these flaws
to bypass certain Java sandbox restrictions. (CVE-2014-6506, CVE-2014-6531,
CVE-2014-6502, CVE-2014-6511, CVE-2014-6504, CVE-2014-6519)

It was discovered that the StAX XML parser in the JAXP component in OpenJDK
performed expansion of external parameter entities even when external
entity substitution was disabled. A remote attacker could use this flaw to
perform XML eXternal Entity (XXE) attack against applications using the
StAX parser to parse untrusted XML documents. (CVE-2014-6517)

It was discovered that the Hotspot component in OpenJDK failed to properly
handle malformed Shared Archive files. A local attacker able to modify a
Shared Archive file used by a virtual machine of a different user could
possibly use this flaw to escalate their privileges. (CVE-2014-6468)

It was discovered that the DatagramSocket implementation in OpenJDK failed
to perform source address checks for packets received on a connected
socket. A remote attacker could use this flaw to have their packets
processed as if they were received from the expected source.
(CVE-2014-6512)

It was discovered that the TLS/SSL implementation in the JSSE component in
OpenJDK failed to properly verify the server identity during the
renegotiation following session resumption, making it possible for
malicious TLS/SSL servers to perform a Triple Handshake attack against
clients using JSSE and client certificate authentication. (CVE-2014-6457)

It was discovered that the CipherInputStream class implementation in
OpenJDK did not properly handle certain exceptions. This could possibly
allow an attacker to affect the integrity of an encrypted stream handled by
this class. (CVE-2014-6558)

The CVE-2014-6512 was discovered by Florian Weimer of Red Hat Product
Security.

All users of java-1.8.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:31.941-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:27.224-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:25.841-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26947 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:56.507-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:13.528-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.8.0-openjdk is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:125351"/>
            <criterion comment="java-1.8.0-openjdk-demo is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:125330"/>
            <criterion comment="java-1.8.0-openjdk-devel is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:125265"/>
            <criterion comment="java-1.8.0-openjdk-headless is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:125269"/>
            <criterion comment="java-1.8.0-openjdk-javadoc is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:124967"/>
            <criterion comment="java-1.8.0-openjdk-src is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:125366"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="java-1.8.0-openjdk-debuginfo is earlier than 0:1.8.0.25-1.b17.el6" test_ref="oval:org.mitre.oval:tst:138301"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26946" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1569 -- wireshark security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1569.html" ref_id="RHSA-2013:1569"/>
        <reference source="CESA-2013:1569" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/001110.html" ref_id="CESA-2013:1569"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2392" ref_id="CVE-2012-2392"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3825" ref_id="CVE-2012-3825"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4285" ref_id="CVE-2012-4285"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4288" ref_id="CVE-2012-4288"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4289" ref_id="CVE-2012-4289"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4290" ref_id="CVE-2012-4290"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4291" ref_id="CVE-2012-4291"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4292" ref_id="CVE-2012-4292"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5595" ref_id="CVE-2012-5595"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5597" ref_id="CVE-2012-5597"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5598" ref_id="CVE-2012-5598"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5599" ref_id="CVE-2012-5599"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5600" ref_id="CVE-2012-5600"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6056" ref_id="CVE-2012-6056"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6059" ref_id="CVE-2012-6059"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6060" ref_id="CVE-2012-6060"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6061" ref_id="CVE-2012-6061"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6062" ref_id="CVE-2012-6062"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3557" ref_id="CVE-2013-3557"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3559" ref_id="CVE-2013-3559"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-3561" ref_id="CVE-2013-3561"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4081" ref_id="CVE-2013-4081"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4083" ref_id="CVE-2013-4083"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4927" ref_id="CVE-2013-4927"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4931" ref_id="CVE-2013-4931"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4932" ref_id="CVE-2013-4932"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4933" ref_id="CVE-2013-4933"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4934" ref_id="CVE-2013-4934"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4935" ref_id="CVE-2013-4935"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4936" ref_id="CVE-2013-4936"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5721" ref_id="CVE-2013-5721"/>
        <description><![CDATA[Wireshark, previously known as Ethereal, is a network protocol analyzer.
It is used to capture and browse the traffic running on a computer network.

Two flaws were found in Wireshark. If Wireshark read a malformed packet off
a network or opened a malicious dump file, it could crash or, possibly,
execute arbitrary code as the user running Wireshark. (CVE-2013-3559,
CVE-2013-4083)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2012-2392, CVE-2012-3825, CVE-2012-4285,
CVE-2012-4288, CVE-2012-4289, CVE-2012-4290, CVE-2012-4291, CVE-2012-4292,
CVE-2012-5595, CVE-2012-5597, CVE-2012-5598, CVE-2012-5599, CVE-2012-5600,
CVE-2012-6056, CVE-2012-6059, CVE-2012-6060, CVE-2012-6061, CVE-2012-6062,
CVE-2013-3557, CVE-2013-3561, CVE-2013-4081, CVE-2013-4927, CVE-2013-4931,
CVE-2013-4932, CVE-2013-4933, CVE-2013-4934, CVE-2013-4935, CVE-2013-4936,
CVE-2013-5721)

The wireshark packages have been upgraded to upstream version 1.8.10, which
provides a number of bug fixes and enhancements over the previous versions.
For more information on the bugs fixed, enhancements included, and
supported protocols introduced, refer to the Wireshark Release Notes,
linked to in the References. (BZ#711024)

This update also fixes the following bugs:

* Previously, Wireshark did not parse the RECLAIM-COMPLETE opcode when
inspecting traffic generated by NFSv4.1. A patch has been provided to
enable the parsing of the RECLAIM_COMPLETE opcode, and Wireshark is now
able to properly dissect and handle NFSv4.1 traffic. (BZ#750712)

* Prior to this update, frame arrival times in a text file were reported
one hour ahead from the timestamps in the packet capture file.
This resulted in various failures being reported by the dfilter-test.py
test suite. To fix this bug, frame arrival timestamps have been shifted by
one hour, thus fixing this bug. (BZ#832021)

* The &quot;tshark -D&quot; command returned output to STDERR instead of STDOUT,
which could break scripts that are parsing the &quot;tshark -D&quot; output. This bug
has been fixed, and the &quot;tshark -D&quot; command now writes output data to a
correct standard stream. (BZ#1004636)

* Due to an array overrun, Wireshark could experience undefined program
behavior or could unexpectedly terminate. With this update, proper array
handling ensures Wireshark no longer crashes in the described scenario.
(BZ#715560)

* Previously, the dftest and randpkt command line utilities lacked manual
pages. This update adds proper manual pages for both utilities. (BZ#659661)

In addition, this update adds the following enhancements:

* With this update, Wireshark is able to properly dissect and handle
InfiniBand and GlusterFS traffic. (BZ#699636, BZ#858976)

All Wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements. All running instances of Wireshark must be restarted for the
update to take effect.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:15:39">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:37.340-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:13.162-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:27.177-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.8.10-4.el6" test_ref="oval:org.mitre.oval:tst:126071"/>
            <criterion comment="wireshark-devel is earlier than 0:1.8.10-4.el6" test_ref="oval:org.mitre.oval:tst:125702"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.8.10-4.el6" test_ref="oval:org.mitre.oval:tst:125544"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="wireshark-debuginfo is earlier than 0:1.8.10-4.el6" test_ref="oval:org.mitre.oval:tst:125684"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26941" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1531 -- qemu-kvm security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1531.html" ref_id="RHSA-2011:1531"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2527" ref_id="CVE-2011-2527"/>
        <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

It was found that qemu-kvm did not properly drop supplemental group
privileges when the root user started guests from the command line
(&amp;quot;/usr/libexec/qemu-kvm&amp;quot;) with the &amp;quot;-runas&amp;quot; option. A qemu-kvm process
started this way could use this flaw to gain access to files on the host
that are accessible to the supplementary groups and not accessible to the
primary group. (CVE-2011-2527)

Note: This issue only affected qemu-kvm when it was started directly from
the command line. It did not affect the Red Hat Enterprise Virtualization
platform or applications that start qemu-kvm via libvirt, such as the
Virtual Machine Manager (virt-manager).

This update also fixes several bugs and adds various enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

All users of qemu-kvm are advised to upgrade to these updated packages,
which contain backported patches to correct these issues and add these
enhancements. After installing this update, shut down all running virtual
machines. Once all virtual machines have shut down, start them again for
this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:04.577-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:12.222-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:26.935-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="qemu-img is earlier than 0:0.12.1.2-2.209.el6" test_ref="oval:org.mitre.oval:tst:126276"/>
          <criterion comment="qemu-kvm is earlier than 0:0.12.1.2-2.209.el6" test_ref="oval:org.mitre.oval:tst:126257"/>
          <criterion comment="qemu-kvm-debuginfo is earlier than 0:0.12.1.2-2.209.el6" test_ref="oval:org.mitre.oval:tst:125938"/>
          <criterion comment="qemu-kvm-tools is earlier than 0:0.12.1.2-2.209.el6" test_ref="oval:org.mitre.oval:tst:126320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26935" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1534 -- nfs-utils security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>nfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1534.html" ref_id="RHSA-2011:1534"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1749" ref_id="CVE-2011-1749"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2500" ref_id="CVE-2011-2500"/>
        <description>The nfs-utils packages provide a daemon for the kernel Network File System
(NFS) server, and related tools such as the mount.nfs, umount.nfs, and
showmount programs.

A flaw was found in the way nfs-utils performed IP based authentication of
mount requests. In configurations where a directory was exported to a group
of systems using a DNS wildcard or NIS (Network Information Service)
netgroup, an attacker could possibly gain access to other directories
exported to a specific host or subnet, bypassing intended access
restrictions. (CVE-2011-2500)

It was found that the mount.nfs tool did not handle certain errors
correctly when updating the mtab (mounted file systems table) file. A local
attacker could use this flaw to corrupt the mtab file. (CVE-2011-1749)

This update also fixes several bugs and adds an enhancement. Documentation
for these bug fixes and the enhancement will be available shortly from the
Technical Notes document, linked to in the References section.

Users of nfs-utils are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues and add this
enhancement. After installing this update, the nfs service will be
restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:09">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:40.864-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:11.879-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:26.713-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="nfs-utils is earlier than 0:1.2.3-15.el6" test_ref="oval:org.mitre.oval:tst:126274"/>
          <criterion comment="nfs-utils-debuginfo is earlier than 0:1.2.3-15.el6" test_ref="oval:org.mitre.oval:tst:126271"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26934" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1741 -- php-pear security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>php-pear</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1741.html" ref_id="RHSA-2011:1741"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1072" ref_id="CVE-2011-1072"/>
        <description><![CDATA[The php-pear package contains the PHP Extension and Application Repository
(PEAR), a framework and distribution system for reusable PHP components.

It was found that the &quot;pear&quot; command created temporary files in an insecure
way when installing packages. A malicious, local user could use this flaw
to conduct a symbolic link attack, allowing them to overwrite the contents
of arbitrary files accessible to the victim running the &quot;pear install&quot;
command. (CVE-2011-1072)

This update also fixes the following bugs:

* The php-pear package has been upgraded to version 1.9.4, which provides a
number of bug fixes over the previous version. (BZ#651897)

* Prior to this update, php-pear created a cache in the
&quot;/var/cache/php-pear/&quot; directory when attempting to list all packages. As a
consequence, php-pear failed to create or update the cache file as a
regular user without sufficient file permissions and could not list all
packages. With this update, php-pear no longer fails if writing to the
cache directory is not permitted. Now, all packages are listed as expected.
(BZ#747361)

All users of php-pear are advised to upgrade to this updated package, which
corrects these issues.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:05">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:55.396-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:11.635-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:26.522-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criterion comment="php-pear is earlier than 0:1.9.4-4.el6" test_ref="oval:org.mitre.oval:tst:126140"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26927" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1507: trousers security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>trousers</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1507-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1507.html"/>
        <reference source="CVE" ref_id="CVE-2012-0698" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0698.html"/>
        <reference source="CESA-2014:1507" ref_id="CESA-2014:1507" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001389.html"/>
        <description>TrouSerS is an implementation of the Trusted Computing Group's Software
Stack (TSS) specification. You can use TrouSerS to write applications that
make use of your TPM hardware. TPM hardware can create, store and use RSA
keys securely (without ever being exposed in memory), verify a platform's
software state using cryptographic hashes and more.

A flaw was found in the way tcsd, the daemon that manages Trusted Computing
resources, processed incoming TCP packets. A remote attacker could send a
specially crafted TCP packet that, when processed by tcsd, could cause the
daemon to crash. Note that by default tcsd accepts requests on localhost
only. (CVE-2012-0698)

Red Hat would like to thank Andrew Lutomirski for reporting this issue.

The trousers package has been upgraded to upstream version 0.3.13, which
provides a number of bug fixes and enhancements over the previous version,
including corrected internal symbol names to avoid collisions with other
applications, fixed memory leaks, added IPv6 support, fixed buffer handling
in tcsd, as well as changed the license to BSD. (BZ#633584, BZ#1074634)

All trousers users are advised to upgrade to these updated packages, which
correct these issues and add these enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:20.864-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:26.218-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:20.262-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26927 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:52.271-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:13.360-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="trousers is earlier than 0:0.3.13-2.el6" test_ref="oval:org.mitre.oval:tst:124549"/>
            <criterion comment="trousers-devel is earlier than 0:0.3.13-2.el6" test_ref="oval:org.mitre.oval:tst:125305"/>
            <criterion comment="trousers-static is earlier than 0:0.3.13-2.el6" test_ref="oval:org.mitre.oval:tst:125151"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="trousers-debuginfo is earlier than 0:0.3.13-2.el6" test_ref="oval:org.mitre.oval:tst:138217"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26917" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1389: krb5 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1389-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1389.html"/>
        <reference source="CVE" ref_id="CVE-2013-1418" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1418.html"/>
        <reference source="CVE" ref_id="CVE-2013-6800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6800.html"/>
        <reference source="CVE" ref_id="CVE-2014-4341" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4341.html"/>
        <reference source="CVE" ref_id="CVE-2014-4342" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4342.html"/>
        <reference source="CVE" ref_id="CVE-2014-4343" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4343.html"/>
        <reference source="CVE" ref_id="CVE-2014-4344" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4344.html"/>
        <reference source="CVE" ref_id="CVE-2014-4345" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4345.html"/>
        <reference source="CESA-2014:1389" ref_id="CESA-2014:1389" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001224.html"/>
        <description>Kerberos is a networked authentication system which allows clients and
servers to authenticate to each other with the help of a trusted third
party, the Kerberos KDC.

It was found that if a KDC served multiple realms, certain requests could
cause the setup_server_realm() function to dereference a NULL pointer.
A remote, unauthenticated attacker could use this flaw to crash the KDC
using a specially crafted request. (CVE-2013-1418, CVE-2013-6800)

A NULL pointer dereference flaw was found in the MIT Kerberos SPNEGO
acceptor for continuation tokens. A remote, unauthenticated attacker could
use this flaw to crash a GSSAPI-enabled server application. (CVE-2014-4344)

A buffer overflow was found in the KADM5 administration server (kadmind)
when it was used with an LDAP back end for the KDC database. A remote,
authenticated attacker could potentially use this flaw to execute arbitrary
code on the system running kadmind. (CVE-2014-4345)

Two buffer over-read flaws were found in the way MIT Kerberos handled
certain requests. A remote, unauthenticated attacker who is able to inject
packets into a client or server application's GSSAPI session could use
either of these flaws to crash the application. (CVE-2014-4341,
CVE-2014-4342)

A double-free flaw was found in the MIT Kerberos SPNEGO initiators.
An attacker able to spoof packets to appear as though they are from an
GSSAPI acceptor could use this flaw to crash a client application that uses
MIT Kerberos. (CVE-2014-4343)

These updated krb5 packages also include several bug fixes. Space precludes
documenting all of these changes in this advisory. Users are directed to
the Red Hat Enterprise Linux 6.6 Technical Notes, linked to in the
References section, for information on the most significant of these
changes.

All krb5 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:21.219-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:25.388-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:17.838-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26917 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:52.085-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:12.956-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="krb5-debuginfo is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:138261"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="krb5-devel is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:124879"/>
            <criterion comment="krb5-libs is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:124306"/>
            <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:124907"/>
            <criterion comment="krb5-server is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:124936"/>
            <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:124840"/>
            <criterion comment="krb5-workstation is earlier than 0:1.10.3-33.el6" test_ref="oval:org.mitre.oval:tst:125280"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26916" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1537 -- augeas security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>augeas</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1537.html" ref_id="RHSA-2013:1537"/>
        <reference source="CESA-2013:1537" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/000897.html" ref_id="CESA-2013:1537"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0786" ref_id="CVE-2012-0786"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0787" ref_id="CVE-2012-0787"/>
        <description><![CDATA[Augeas is a utility for editing configuration. Augeas parses configuration
files in their native formats and transforms them into a tree.
Configuration changes are made by manipulating this tree and saving it back
into native configuration files. Augeas also uses &quot;lenses&quot; as basic
building blocks for establishing the mapping from files into the Augeas
tree and back.

Multiple flaws were found in the way Augeas handled configuration files
when updating them. An application using Augeas to update configuration
files in a directory that is writable to by a different user (for example,
an application running as root that is updating files in a directory owned
by a non-root service user) could have been tricked into overwriting
arbitrary files or leaking information via a symbolic link or mount point
attack. (CVE-2012-0786, CVE-2012-0787)

The augeas package has been upgraded to upstream version 1.0.0, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#817753)

This update also fixes the following bugs:

* Previously, when single quotes were used in an XML attribute, Augeas was
unable to parse the file with the XML lens. An upstream patch has been
provided ensuring that single quotes are handled as valid characters and
parsing no longer fails. (BZ#799885)

* Prior to this update, Augeas was unable to set up the &quot;require_ssl_reuse&quot;
option in the vsftpd.conf file. The updated patch fixes the vsftpd lens to
properly recognize this option, thus fixing this bug. (BZ#855022)

* Previously, the XML lens did not support non-Unix line endings.
Consequently, Augeas was unable to load any files containing such line
endings. The XML lens has been fixed to handle files with CRLF line
endings, thus fixing this bug. (BZ#799879)

* Previously, Augeas was unable to parse modprobe.conf files with spaces
around &quot;=&quot; characters in option directives. The modprobe lens has been
updated and parsing no longer fails. (BZ#826752)

All Augeas users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:15:39">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:39.611-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:07.788-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:26.288-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="augeas is earlier than 0:1.0.0-5.el6" test_ref="oval:org.mitre.oval:tst:126099"/>
            <criterion comment="augeas-devel is earlier than 0:1.0.0-5.el6" test_ref="oval:org.mitre.oval:tst:126098"/>
            <criterion comment="augeas-libs is earlier than 0:1.0.0-5.el6" test_ref="oval:org.mitre.oval:tst:125418"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="augeas-debuginfo is earlier than 0:1.0.0-5.el6" test_ref="oval:org.mitre.oval:tst:125940"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26915" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1657: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1657-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1657.html"/>
        <reference source="CVE" ref_id="CVE-2014-4288" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4288.html"/>
        <reference source="CVE" ref_id="CVE-2014-6456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6456.html"/>
        <reference source="CVE" ref_id="CVE-2014-6457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6457.html"/>
        <reference source="CVE" ref_id="CVE-2014-6458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6458.html"/>
        <reference source="CVE" ref_id="CVE-2014-6476" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6476.html"/>
        <reference source="CVE" ref_id="CVE-2014-6492" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6492.html"/>
        <reference source="CVE" ref_id="CVE-2014-6493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6493.html"/>
        <reference source="CVE" ref_id="CVE-2014-6502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6502.html"/>
        <reference source="CVE" ref_id="CVE-2014-6503" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6503.html"/>
        <reference source="CVE" ref_id="CVE-2014-6504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6504.html"/>
        <reference source="CVE" ref_id="CVE-2014-6506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6506.html"/>
        <reference source="CVE" ref_id="CVE-2014-6511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6511.html"/>
        <reference source="CVE" ref_id="CVE-2014-6512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6512.html"/>
        <reference source="CVE" ref_id="CVE-2014-6515" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6515.html"/>
        <reference source="CVE" ref_id="CVE-2014-6517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6517.html"/>
        <reference source="CVE" ref_id="CVE-2014-6519" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6519.html"/>
        <reference source="CVE" ref_id="CVE-2014-6527" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6527.html"/>
        <reference source="CVE" ref_id="CVE-2014-6531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6531.html"/>
        <reference source="CVE" ref_id="CVE-2014-6532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6532.html"/>
        <reference source="CVE" ref_id="CVE-2014-6558" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6558.html"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-4288, CVE-2014-6456, CVE-2014-6457, CVE-2014-6458, CVE-2014-6476,
CVE-2014-6492, CVE-2014-6493, CVE-2014-6502, CVE-2014-6503, CVE-2014-6504,
CVE-2014-6506, CVE-2014-6511, CVE-2014-6512, CVE-2014-6515, CVE-2014-6517,
CVE-2014-6519, CVE-2014-6527, CVE-2014-6531, CVE-2014-6532, CVE-2014-6558)

The CVE-2014-6512 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 72 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:26.774-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:23.645-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:15.647-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26915 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:40.039-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:45.903-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:140719"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:140918"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:140948"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:141211"/>
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:141212"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.4.el5_11" test_ref="oval:org.mitre.oval:tst:141161"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:124966"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125290"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125339"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125348"/>
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125233"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:125274"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141226"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141191"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:140729"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:140953"/>
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141116"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.2.el7" test_ref="oval:org.mitre.oval:tst:141169"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26914" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1581 -- ruby security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1581.html" ref_id="RHSA-2011:1581"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2705" ref_id="CVE-2011-2705"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3009" ref_id="CVE-2011-3009"/>
        <description>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

It was found that Ruby did not reinitialize the PRNG (pseudorandom number
generator) after forking a child process. This could eventually lead to the
PRNG returning the same result twice. An attacker keeping track of the
values returned by one child process could use this flaw to predict the
values the PRNG would return in other child processes (as long as the
parent process persisted). (CVE-2011-3009)

A flaw was found in the Ruby SecureRandom module. When using the
SecureRandom.random_bytes class, the PRNG state was not modified after
forking a child process. This could eventually lead to
SecureRandom.random_bytes returning the same string more than once. An
attacker keeping track of the strings returned by one child process could
use this flaw to predict the strings SecureRandom.random_bytes would return
in other child processes (as long as the parent process persisted).
(CVE-2011-2705)

This update also fixes the following bugs:

* The ruby package has been upgraded to upstream point release 1.8.7-p352,
which provides a number of bug fixes over the previous version. (BZ#706332)

* The MD5 message-digest algorithm is not a FIPS-approved algorithm.
Consequently, when a Ruby script attempted to calculate an MD5 checksum in
FIPS mode, the interpreter terminated unexpectedly. This bug has been fixed
and an exception is now raised in the described scenario. (BZ#717709)

* Due to inappropriately handled line continuations in the mkconfig.rb
source file, an attempt to build the ruby package resulted in unexpected
termination. An upstream patch has been applied to address this issue and
the ruby package can now be built properly. (BZ#730287)

* When the 32-bit ruby-libs library was installed on a 64-bit machine, the
mkmf library failed to load various modules necessary for building
Ruby-related packages. This bug has been fixed and mkmf now works properly
in the described scenario. (BZ#674787)

* Previously, the load paths for scripts and binary modules were duplicated
on the i386 architecture. Consequently, an ActiveSupport test failed. With
this update, the load paths are no longer stored in duplicates on the i386
architecture. (BZ#722887)

This update also adds the following enhancement:

* With this update, SystemTap probes have been added to the ruby package.
(BZ#673162)

All users of ruby are advised to upgrade to these updated packages, which
resolve these issues and add this enhancement.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:13">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:43.813-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:07.393-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:26.021-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="ruby is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:126299"/>
          <criterion comment="ruby-debuginfo is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:126136"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:126127"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:125937"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:126290"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:125924"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:126112"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:125473"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:125358"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-3.el6" test_ref="oval:org.mitre.oval:tst:126312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26899" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1635: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1635-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1635.html"/>
        <reference source="CESA" ref_id="CESA-2014:1635"/>
        <reference source="CVE" ref_id="CVE-2014-1574" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1574.html"/>
        <reference source="CVE" ref_id="CVE-2014-1576" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1576.html"/>
        <reference source="CVE" ref_id="CVE-2014-1577" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1577.html"/>
        <reference source="CVE" ref_id="CVE-2014-1578" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1578.html"/>
        <reference source="CVE" ref_id="CVE-2014-1581" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1581.html"/>
        <reference source="CVE" ref_id="CVE-2014-1583" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1583.html"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1574, CVE-2014-1578, CVE-2014-1581, CVE-2014-1576,
CVE-2014-1577)

A flaw was found in the Alarm API, which allows applications to schedule
actions to be run in the future. A malicious web application could use this
flaw to bypass cross-origin restrictions. (CVE-2014-1583)

Red Hat would like to thank the Mozilla project for reporting these issues. 
Upstream acknowledges Bobby Holley, Christian Holler, David Bolter, Byron 
Campen Jon Coppeard, Atte Kettunen, Holger Fuhrmannek, Abhishek Arya, 
regenrecht, and Boris Zbarsky as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 31.2.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 31.2.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:28.428-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:22.422-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:01:11.417-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:31.2.0-3.el5_11" test_ref="oval:org.mitre.oval:tst:125381"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:31.2.0-3.el5.centos" test_ref="oval:org.mitre.oval:tst:125077"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 7 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:31.2.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:125354"/>
            <criterion comment="xulrunner-devel is earlier than 0:31.2.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:125313"/>
            <criterion comment="firefox is earlier than 0:31.2.0-3.el7_0" test_ref="oval:org.mitre.oval:tst:125112"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 7 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:31.2.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:125349"/>
            <criterion comment="xulrunner-devel is earlier than 0:31.2.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:125107"/>
            <criterion comment="firefox is earlier than 0:31.2.0-3.el7.centos" test_ref="oval:org.mitre.oval:tst:124713"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="firefox is earlier than 0:31.2.0-3.el6_6" test_ref="oval:org.mitre.oval:tst:125356"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26890" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1676 -- wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1676.html" ref_id="RHSA-2014:1676"/>
        <reference source="CESA-2014:1676" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020702.html" ref_id="CESA-2014:1676"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6421" ref_id="CVE-2014-6421"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6422" ref_id="CVE-2014-6422"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6423" ref_id="CVE-2014-6423"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6424" ref_id="CVE-2014-6424"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6425" ref_id="CVE-2014-6425"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6426" ref_id="CVE-2014-6426"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6427" ref_id="CVE-2014-6427"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6428" ref_id="CVE-2014-6428"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6429" ref_id="CVE-2014-6429"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6430" ref_id="CVE-2014-6430"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6431" ref_id="CVE-2014-6431"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6432" ref_id="CVE-2014-6432"/>
        <description>Wireshark is a network protocol analyzer. It is used to capture and browse
the traffic running on a computer network.

Multiple flaws were found in Wireshark. If Wireshark read a malformed
packet off a network or opened a malicious dump file, it could crash or,
possibly, execute arbitrary code as the user running Wireshark.
(CVE-2014-6429, CVE-2014-6430, CVE-2014-6431, CVE-2014-6432)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2014-6421, CVE-2014-6422, CVE-2014-6423,
CVE-2014-6424, CVE-2014-6425, CVE-2014-6426, CVE-2014-6427, CVE-2014-6428)

All wireshark users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running instances
of Wireshark must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:49">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:50.278-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:01:03.524-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:24.706-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.8.10-8.el6_6" test_ref="oval:org.mitre.oval:tst:125214"/>
            <criterion comment="wireshark-devel is earlier than 0:1.8.10-8.el6_6" test_ref="oval:org.mitre.oval:tst:125647"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.8.10-8.el6_6" test_ref="oval:org.mitre.oval:tst:125950"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="wireshark-debuginfo is earlier than 0:1.8.10-8.el6_6" test_ref="oval:org.mitre.oval:tst:125925"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="wireshark is earlier than 0:1.10.3-12.el7_0" test_ref="oval:org.mitre.oval:tst:125989"/>
            <criterion comment="wireshark-devel is earlier than 0:1.10.3-12.el7_0" test_ref="oval:org.mitre.oval:tst:125961"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.10.3-12.el7_0" test_ref="oval:org.mitre.oval:tst:125127"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criterion comment="wireshark-debuginfo is earlier than 0:1.10.3-12.el7_0" test_ref="oval:org.mitre.oval:tst:125819"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26829" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1652: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1652-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1652.html"/>
        <reference source="CESA" ref_id="CESA-2014:1652"/>
        <reference source="CVE" ref_id="CVE-2014-3513" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3513.html"/>
        <reference source="CVE" ref_id="CVE-2014-3567" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3567.html"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL),
Transport Layer Security (TLS), and Datagram Transport Layer Security
(DTLS) protocols, as well as a full-strength, general purpose cryptography
library.

This update adds support for the TLS Fallback Signaling Cipher Suite Value
(TLS_FALLBACK_SCSV), which can be used to prevent protocol downgrade
attacks against applications which re-connect using a lower SSL/TLS
protocol version when the initial connection indicating the highest
supported protocol version fails.

This can prevent a forceful downgrade of the communication to SSL 3.0.
The SSL 3.0 protocol was found to be vulnerable to the padding oracle
attack when using block cipher suites in cipher block chaining (CBC) mode.
This issue is identified as CVE-2014-3566, and also known under the alias
POODLE. This SSL 3.0 protocol flaw will not be addressed in a future
update; it is recommended that users configure their applications to
require at least TLS protocol version 1.0 for secure communication.

For additional information about this flaw, see the Knowledgebase article
at https://access.redhat.com/articles/1232123

A memory leak flaw was found in the way OpenSSL parsed the DTLS Secure
Real-time Transport Protocol (SRTP) extension data. A remote attacker could
send multiple specially crafted handshake messages to exhaust all available
memory of an SSL/TLS or DTLS server. (CVE-2014-3513)

A memory leak flaw was found in the way an OpenSSL handled failed session
ticket integrity checks. A remote attacker could exhaust all available
memory of an SSL/TLS or DTLS server by sending a large number of invalid
session tickets to that server. (CVE-2014-3567)

All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to mitigate the CVE-2014-3566 issue and correct
the CVE-2014-3513 and CVE-2014-3567 issues. For the update to take effect,
all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:31.411-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:21.392-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:57.821-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl is earlier than 1:1.0.1e-34.el7_0.6" test_ref="oval:org.mitre.oval:tst:124930"/>
            <criterion comment="openssl-devel is earlier than 1:1.0.1e-34.el7_0.6" test_ref="oval:org.mitre.oval:tst:124834"/>
            <criterion comment="openssl-libs is earlier than 1:1.0.1e-34.el7_0.6" test_ref="oval:org.mitre.oval:tst:124864"/>
            <criterion comment="openssl-perl is earlier than 1:1.0.1e-34.el7_0.6" test_ref="oval:org.mitre.oval:tst:125085"/>
            <criterion comment="openssl-static is earlier than 1:1.0.1e-34.el7_0.6" test_ref="oval:org.mitre.oval:tst:125405"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl is earlier than 0:1.0.1e-30.el6_6.2" test_ref="oval:org.mitre.oval:tst:124925"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.1e-30.el6_6.2" test_ref="oval:org.mitre.oval:tst:124881"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.1e-30.el6_6.2" test_ref="oval:org.mitre.oval:tst:125398"/>
            <criterion comment="openssl-static is earlier than 0:1.0.1e-30.el6_6.2" test_ref="oval:org.mitre.oval:tst:124481"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26820" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1193: axis security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>axis</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1193-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1193.html"/>
        <reference source="CESA" ref_id="CESA-2014:1193"/>
        <reference source="CVE" ref_id="CVE-2014-3596" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3596.html"/>
        <description>Apache Axis is an implementation of SOAP (Simple Object Access Protocol).
It can be used to build both web service clients and servers.

It was discovered that Axis incorrectly extracted the host name from an
X.509 certificate subject's Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3596)

For additional information on this flaw, refer to the Knowledgebase article
in the References section.

This issue was discovered by David Jorm and Arun Neelicattu of Red Hat
Product Security.

All axis users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. Applications using Apache
Axis must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:09.637-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:56.528-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:02:05.063-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="axis is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:123908"/>
            <criterion comment="axis-javadoc is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:123895"/>
            <criterion comment="axis-manual is earlier than 0:1.2.1-2jpp.8.el5_10" test_ref="oval:org.mitre.oval:tst:123598"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="axis is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:123761"/>
            <criterion comment="axis-javadoc is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:123903"/>
            <criterion comment="axis-manual is earlier than 0:1.2.1-7.5.el6_5" test_ref="oval:org.mitre.oval:tst:123658"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26816" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1671 -- rsyslog5 and rsyslog security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>rsyslog</product>
          <product>rsyslog5</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1671.html" ref_id="RHSA-2014:1671"/>
        <reference source="CESA-2014:1671" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-October/020699.html" ref_id="CESA-2014:1671"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3634" ref_id="CVE-2014-3634"/>
        <description>The rsyslog packages provide an enhanced, multi-threaded syslog daemon
that supports writing to relational databases, syslog/TCP, RFC 3195,
permitted sender lists, filtering on any message part, and fine grained
output format control.

A flaw was found in the way rsyslog handled invalid log message priority
values. In certain configurations, a local attacker, or a remote attacker
able to connect to the rsyslog port, could use this flaw to crash the
rsyslog daemon. (CVE-2014-3634)

Red Hat would like to thank Rainer Gerhards of rsyslog upstream for
reporting this issue.

All rsyslog5 and rsyslog users are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing the update, the rsyslog service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:14:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:48:07.936-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:00:56.610-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:23.464-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rsyslog5 is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125788"/>
            <criterion comment="rsyslog5-gnutls is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125806"/>
            <criterion comment="rsyslog5-gssapi is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125803"/>
            <criterion comment="rsyslog5-mysql is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125338"/>
            <criterion comment="rsyslog5-pgsql is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125906"/>
            <criterion comment="rsyslog5-snmp is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125639"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="rsyslog5-debuginfo is earlier than 0:5.8.12-5.el5_11" test_ref="oval:org.mitre.oval:tst:125903"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rsyslog is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125524"/>
            <criterion comment="rsyslog-gnutls is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125503"/>
            <criterion comment="rsyslog-gssapi is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125716"/>
            <criterion comment="rsyslog-mysql is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125517"/>
            <criterion comment="rsyslog-pgsql is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125341"/>
            <criterion comment="rsyslog-relp is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125650"/>
            <criterion comment="rsyslog-snmp is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125530"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="rsyslog-debuginfo is earlier than 0:5.8.10-9.el6_6" test_ref="oval:org.mitre.oval:tst:125854"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26805" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1552: openssh security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1552-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1552.html"/>
        <reference source="CVE" ref_id="CVE-2014-2532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2532.html"/>
        <reference source="CVE" ref_id="CVE-2014-2653" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2653.html"/>
        <reference source="CESA-2014:1552" ref_id="CESA-2014:1552" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001318.html"/>
        <description>OpenSSH is OpenBSD's SSH (Secure Shell) protocol implementation.
These packages include the core files necessary for both the OpenSSH client
and server.

It was discovered that OpenSSH clients did not correctly verify DNS SSHFP
records. A malicious server could use this flaw to force a connecting
client to skip the DNS SSHFP record check and require the user to perform
manual host verification of the DNS SSHFP record. (CVE-2014-2653)

It was found that OpenSSH did not properly handle certain AcceptEnv
parameter values with wildcard characters. A remote attacker could use this
flaw to bypass intended environment variable restrictions. (CVE-2014-2532)

This update also fixes the following bugs:

* Based on the SP800-131A information security standard, the generation of
a digital signature using the Digital Signature Algorithm (DSA) with the
key size of 1024 bits and RSA with the key size of less than 2048 bits is
disallowed after the year 2013. After this update, ssh-keygen no longer
generates keys with less than 2048 bits in FIPS mode. However, the sshd
service accepts keys of size 1024 bits as well as larger keys for
compatibility reasons. (BZ#993580)

* Previously, the openssh utility incorrectly set the oom_adj value to -17
for all of its children processes. This behavior was incorrect because the
children processes were supposed to have this value set to 0. This update
applies a patch to fix this bug and oom_adj is now properly set to 0 for
all children processes as expected. (BZ#1010429)

* Previously, if the sshd service failed to verify the checksum of an
installed FIPS module using the fipscheck library, the information about
this failure was only provided at the standard error output of sshd. As a
consequence, the user could not notice this message and be uninformed when
a system had not been properly configured for FIPS mode. To fix this bug,
this behavior has been changed and sshd now sends such messages via the
syslog service. (BZ#1020803)

* When keys provided by the pkcs11 library were removed from the ssh agent
using the "ssh-add -e" command, the user was prompted to enter a PIN.
With this update, a patch has been applied to allow the user to remove the
keys provided by pkcs11 without the PIN. (BZ#1042519)

In addition, this update adds the following enhancements:

* With this update, ControlPersist has been added to OpenSSH. The option in
conjunction with the ControlMaster configuration directive specifies that
the master connection remains open in the background after the initial
client connection has been closed. (BZ#953088)

* When the sshd daemon is configured to force the internal SFTP session,
and the user attempts to use a connection other than SFTP, the appropriate
message is logged to the /var/log/secure file. (BZ#997377)

* Support for Elliptic Curve Cryptography modes for key exchange (ECDH) and
host user keys (ECDSA) as specified by RFC5656 has been added to the
openssh packages. However, they are not enabled by default and the user has
to enable them manually. For more information on how to configure ECDSA and
ECDH with OpenSSH, see: https://access.redhat.com/solutions/711953
(BZ#1028335)

All openssh users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:25.295-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:20.900-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:56.609-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26805 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:54.703-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:12.180-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssh is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:125098"/>
            <criterion comment="openssh-askpass is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:125378"/>
            <criterion comment="openssh-clients is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:125037"/>
            <criterion comment="openssh-ldap is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:124984"/>
            <criterion comment="openssh-server is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:124560"/>
            <criterion comment="pam_ssh_agent_auth is earlier than 0:0.9.3-104.el6" test_ref="oval:org.mitre.oval:tst:125340"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="openssh-debuginfo is earlier than 0:5.3p1-104.el6" test_ref="oval:org.mitre.oval:tst:138319"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26787" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1526 -- glibc security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1526.html" ref_id="RHSA-2011:1526"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5064" ref_id="CVE-2009-5064"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1089" ref_id="CVE-2011-1089"/>
        <description>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system
cannot function properly.

A flaw was found in the way the ldd utility identified dynamically linked
libraries. If an attacker could trick a user into running ldd on a
malicious binary, it could result in arbitrary code execution with the
privileges of the user running ldd. (CVE-2009-5064)

It was found that the glibc addmntent() function, used by various mount
helper utilities, did not handle certain errors correctly when updating the
mtab (mounted file systems table) file. If such utilities had the setuid
bit set, a local attacker could use this flaw to corrupt the mtab file.
(CVE-2011-1089)

Red Hat would like to thank Dan Rosenberg for reporting the CVE-2011-1089
issue.

This update also fixes several bugs and adds various enhancements.
Documentation for these bug fixes and enhancements will be available
shortly from the Technical Notes document, linked to in the References
section.

Users are advised to upgrade to these updated glibc packages, which contain
backported patches to resolve these issues and add these enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:16:08">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:58.943-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:00:53.458-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:22.473-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages match section">
          <criterion comment="glibc is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:126022"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:125973"/>
          <criterion comment="glibc-debuginfo is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:125976"/>
          <criterion comment="glibc-debuginfo-common is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:125901"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:125334"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:126200"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:125984"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:126122"/>
          <criterion comment="nscd is earlier than 0:2.12-1.47.el6" test_ref="oval:org.mitre.oval:tst:126296"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26778" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1167: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1167-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1167.html"/>
        <reference source="CESA" ref_id="CESA-2014:1167"/>
        <reference source="CVE" ref_id="CVE-2014-0205" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0205.html"/>
        <reference source="CVE" ref_id="CVE-2014-3535" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3535.html"/>
        <reference source="CVE" ref_id="CVE-2014-3917" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3917.html"/>
        <reference source="CVE" ref_id="CVE-2014-4667" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4667.html"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's futex subsystem handled
reference counting when requeuing futexes during futex_wait(). A local,
unprivileged user could use this flaw to zero out the reference counter of
an inode or an mm struct that backs up the memory area of the futex, which
could lead to a use-after-free flaw, resulting in a system crash or,
potentially, privilege escalation. (CVE-2014-0205, Important)

* A NULL pointer dereference flaw was found in the way the Linux kernel's
networking implementation handled logging while processing certain invalid
packets coming in via a VxLAN interface. A remote attacker could use this
flaw to crash the system by sending a specially crafted packet to such an
interface. (CVE-2014-3535, Important)

* An out-of-bounds memory access flaw was found in the Linux kernel's
system call auditing implementation. On a system with existing audit rules
defined, a local, unprivileged user could use this flaw to leak kernel
memory to user space or, potentially, crash the system. (CVE-2014-3917,
Moderate)

* An integer underflow flaw was found in the way the Linux kernel's Stream
Control Transmission Protocol (SCTP) implementation processed certain
COOKIE_ECHO packets. By sending a specially crafted SCTP packet, a remote
attacker could use this flaw to prevent legitimate connections to a
particular SCTP server socket to be made. (CVE-2014-4667, Moderate)

Red Hat would like to thank Gopal Reddy Kodudula of Nokia Siemens Networks
for reporting CVE-2014-4667. The security impact of the CVE-2014-0205 issue
was discovered by Mateusz Guzik of Red Hat.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:10.303-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:53.064-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:56.984-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123813"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123669"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:122932"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123394"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123755"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123750"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123144"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123779"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123742"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123660"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123872"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:123353"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.29.2.el6" test_ref="oval:org.mitre.oval:tst:122937"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26767" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1654: rsyslog7 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>rsyslog7</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1654-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1654.html"/>
        <reference source="CVE" ref_id="CVE-2014-3634" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3634.html"/>
        <reference source="CESA-2014:1654" ref_id="CESA-2014:1654" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001478.html"/>
        <description>The rsyslog7 packages provide an enhanced, multi-threaded syslog daemon
that supports writing to relational databases, syslog/TCP, RFC 3195,
permitted sender lists, filtering on any message part, and fine grained
output format control.

A flaw was found in the way rsyslog handled invalid log message priority
values. In certain configurations, a local attacker, or a remote attacker
able to connect to the rsyslog port, could use this flaw to crash the
rsyslog daemon or, potentially, execute arbitrary code as the user running
the rsyslog daemon. (CVE-2014-3634)

Red Hat would like to thank Rainer Gerhards of rsyslog upstream for
reporting this issue.

All rsyslog7 users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the rsyslog service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:24.396-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:19.452-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:53.215-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26767 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:51.175-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:11.606-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rsyslog7 is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:125385"/>
            <criterion comment="rsyslog7-elasticsearch is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:125318"/>
            <criterion comment="rsyslog7-gnutls is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:124940"/>
            <criterion comment="rsyslog7-gssapi is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:125230"/>
            <criterion comment="rsyslog7-mysql is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:125297"/>
            <criterion comment="rsyslog7-pgsql is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:125258"/>
            <criterion comment="rsyslog7-relp is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:125287"/>
            <criterion comment="rsyslog7-snmp is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:124421"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="rsyslog7-debuginfo is earlier than 0:7.4.10-3.el6_6" test_ref="oval:org.mitre.oval:tst:138264"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26759" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1436: X11 client libraries security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libX11</product>
          <product>libXcursor</product>
          <product>libXext</product>
          <product>libXfixes</product>
          <product>libXi</product>
          <product>libXinerama</product>
          <product>libXp</product>
          <product>libXrandr</product>
          <product>libXrender</product>
          <product>libXres</product>
          <product>libXt</product>
          <product>libXtst</product>
          <product>libXv</product>
          <product>libXvMC</product>
          <product>libXxf86dga</product>
          <product>libXxf86vm</product>
          <product>libdmx</product>
          <product>libxcb</product>
          <product>xcb-proto</product>
          <product>xkeyboard-config</product>
          <product>xorg-x11-proto-devel</product>
          <product>xorg-x11-xtrans-devel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1436-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1436.html"/>
        <reference source="CVE" ref_id="CVE-2013-1981" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1981.html"/>
        <reference source="CVE" ref_id="CVE-2013-1982" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1982.html"/>
        <reference source="CVE" ref_id="CVE-2013-1983" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1983.html"/>
        <reference source="CVE" ref_id="CVE-2013-1984" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1984.html"/>
        <reference source="CVE" ref_id="CVE-2013-1985" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1985.html"/>
        <reference source="CVE" ref_id="CVE-2013-1986" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1986.html"/>
        <reference source="CVE" ref_id="CVE-2013-1987" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1987.html"/>
        <reference source="CVE" ref_id="CVE-2013-1988" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1988.html"/>
        <reference source="CVE" ref_id="CVE-2013-1989" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1989.html"/>
        <reference source="CVE" ref_id="CVE-2013-1990" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1990.html"/>
        <reference source="CVE" ref_id="CVE-2013-1991" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1991.html"/>
        <reference source="CVE" ref_id="CVE-2013-1995" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1995.html"/>
        <reference source="CVE" ref_id="CVE-2013-1997" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1997.html"/>
        <reference source="CVE" ref_id="CVE-2013-1998" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1998.html"/>
        <reference source="CVE" ref_id="CVE-2013-1999" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1999.html"/>
        <reference source="CVE" ref_id="CVE-2013-2000" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2000.html"/>
        <reference source="CVE" ref_id="CVE-2013-2001" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2001.html"/>
        <reference source="CVE" ref_id="CVE-2013-2002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2002.html"/>
        <reference source="CVE" ref_id="CVE-2013-2003" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2003.html"/>
        <reference source="CVE" ref_id="CVE-2013-2004" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2004.html"/>
        <reference source="CVE" ref_id="CVE-2013-2005" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2005.html"/>
        <reference source="CVE" ref_id="CVE-2013-2062" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2062.html"/>
        <reference source="CVE" ref_id="CVE-2013-2064" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2064.html"/>
        <reference source="CVE" ref_id="CVE-2013-2066" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2066.html"/>
        <reference source="CESA-2014:1436" ref_id="CESA-2014:1436-CentOS 6" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001233.html"/>
        <description>The X11 (Xorg) libraries provide library routines that are used within all
X Window applications.

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the way various X11 client libraries handled certain protocol
data. An attacker able to submit invalid protocol data to an X11 server via
a malicious X11 client could use either of these flaws to potentially
escalate their privileges on the system. (CVE-2013-1981, CVE-2013-1982,
CVE-2013-1983, CVE-2013-1984, CVE-2013-1985, CVE-2013-1986, CVE-2013-1987,
CVE-2013-1988, CVE-2013-1989, CVE-2013-1990, CVE-2013-1991, CVE-2013-2003,
CVE-2013-2062, CVE-2013-2064)

Multiple array index errors, leading to heap-based buffer out-of-bounds
write flaws, were found in the way various X11 client libraries handled
data returned from an X11 server. A malicious X11 server could possibly use
this flaw to execute arbitrary code with the privileges of the user running
an X11 client. (CVE-2013-1997, CVE-2013-1998, CVE-2013-1999, CVE-2013-2000,
CVE-2013-2001, CVE-2013-2002, CVE-2013-2066)

A buffer overflow flaw was found in the way the XListInputDevices()
function of X.Org X11's libXi runtime library handled signed numbers.
A malicious X11 server could possibly use this flaw to execute arbitrary
code with the privileges of the user running an X11 client. (CVE-2013-1995)

A flaw was found in the way the X.Org X11 libXt runtime library used
uninitialized pointers. A malicious X11 server could possibly use this flaw
to execute arbitrary code with the privileges of the user running an X11
client. (CVE-2013-2005)

Two stack-based buffer overflow flaws were found in the way libX11, the
Core X11 protocol client library, processed certain user-specified files.
A malicious X11 server could possibly use this flaw to crash an X11 client
via a specially crafted file. (CVE-2013-2004)

The xkeyboard-config package has been upgraded to upstream version 2.11,
which provides a number of bug fixes and enhancements over the previous
version. (BZ#1077471)

This update also fixes the following bugs:

* Previously, updating the mesa-libGL package did not update the libX11
package, although it was listed as a dependency of mesa-libGL. This bug has
been fixed and updating mesa-libGL now updates all dependent packages as
expected. (BZ#1054614)

* Previously, closing a customer application could occasionally cause the X
Server to terminate unexpectedly. After this update, the X Server no longer
hangs when a user closes a customer application. (BZ#971626)

All X11 client libraries users are advised to upgrade to these updated
packages, which correct these issues and add these enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:22.784-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:17.396-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:50.051-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26759 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:54.078-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:10.018-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libX11 is earlier than 0:1.6.0-2.2.el6" test_ref="oval:org.mitre.oval:tst:125369"/>
            <criterion comment="libX11-common is earlier than 0:1.6.0-2.2.el6" test_ref="oval:org.mitre.oval:tst:125194"/>
            <criterion comment="libX11-devel is earlier than 0:1.6.0-2.2.el6" test_ref="oval:org.mitre.oval:tst:125388"/>
            <criterion comment="libXcursor is earlier than 0:1.1.14-2.1.el6" test_ref="oval:org.mitre.oval:tst:124987"/>
            <criterion comment="libXcursor-devel is earlier than 0:1.1.14-2.1.el6" test_ref="oval:org.mitre.oval:tst:124853"/>
            <criterion comment="libXext is earlier than 0:1.3.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:124897"/>
            <criterion comment="libXext-devel is earlier than 0:1.3.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:125155"/>
            <criterion comment="libXfixes is earlier than 0:5.0.1-2.1.el6" test_ref="oval:org.mitre.oval:tst:125106"/>
            <criterion comment="libXfixes-devel is earlier than 0:5.0.1-2.1.el6" test_ref="oval:org.mitre.oval:tst:125219"/>
            <criterion comment="libXi is earlier than 0:1.7.2-2.2.el6" test_ref="oval:org.mitre.oval:tst:125097"/>
            <criterion comment="libXi-devel is earlier than 0:1.7.2-2.2.el6" test_ref="oval:org.mitre.oval:tst:125283"/>
            <criterion comment="libXinerama is earlier than 0:1.1.3-2.1.el6" test_ref="oval:org.mitre.oval:tst:125175"/>
            <criterion comment="libXinerama-devel is earlier than 0:1.1.3-2.1.el6" test_ref="oval:org.mitre.oval:tst:125195"/>
            <criterion comment="libXp is earlier than 0:1.0.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:124902"/>
            <criterion comment="libXp-devel is earlier than 0:1.0.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:125167"/>
            <criterion comment="libXrandr is earlier than 0:1.4.1-2.1.el6" test_ref="oval:org.mitre.oval:tst:124396"/>
            <criterion comment="libXrandr-devel is earlier than 0:1.4.1-2.1.el6" test_ref="oval:org.mitre.oval:tst:125396"/>
            <criterion comment="libXrender is earlier than 0:0.9.8-2.1.el6" test_ref="oval:org.mitre.oval:tst:125251"/>
            <criterion comment="libXrender-devel is earlier than 0:0.9.8-2.1.el6" test_ref="oval:org.mitre.oval:tst:125255"/>
            <criterion comment="libXres is earlier than 0:1.0.7-2.1.el6" test_ref="oval:org.mitre.oval:tst:124895"/>
            <criterion comment="libXres-devel is earlier than 0:1.0.7-2.1.el6" test_ref="oval:org.mitre.oval:tst:125197"/>
            <criterion comment="libXt is earlier than 0:1.1.4-6.1.el6" test_ref="oval:org.mitre.oval:tst:125247"/>
            <criterion comment="libXt-devel is earlier than 0:1.1.4-6.1.el6" test_ref="oval:org.mitre.oval:tst:125070"/>
            <criterion comment="libXtst is earlier than 0:1.2.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:125143"/>
            <criterion comment="libXtst-devel is earlier than 0:1.2.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:125389"/>
            <criterion comment="libXv is earlier than 0:1.0.9-2.1.el6" test_ref="oval:org.mitre.oval:tst:124708"/>
            <criterion comment="libXv-devel is earlier than 0:1.0.9-2.1.el6" test_ref="oval:org.mitre.oval:tst:125186"/>
            <criterion comment="libXvMC is earlier than 0:1.0.8-2.1.el6" test_ref="oval:org.mitre.oval:tst:124530"/>
            <criterion comment="libXvMC-devel is earlier than 0:1.0.8-2.1.el6" test_ref="oval:org.mitre.oval:tst:125357"/>
            <criterion comment="libXxf86dga is earlier than 0:1.1.4-2.1.el6" test_ref="oval:org.mitre.oval:tst:125392"/>
            <criterion comment="libXxf86dga-devel is earlier than 0:1.1.4-2.1.el6" test_ref="oval:org.mitre.oval:tst:125363"/>
            <criterion comment="libXxf86vm is earlier than 0:1.1.3-2.1.el6" test_ref="oval:org.mitre.oval:tst:125057"/>
            <criterion comment="libXxf86vm-devel is earlier than 0:1.1.3-2.1.el6" test_ref="oval:org.mitre.oval:tst:125302"/>
            <criterion comment="libdmx is earlier than 0:1.1.3-3.el6" test_ref="oval:org.mitre.oval:tst:125309"/>
            <criterion comment="libdmx-devel is earlier than 0:1.1.3-3.el6" test_ref="oval:org.mitre.oval:tst:125240"/>
            <criterion comment="libxcb is earlier than 0:1.9.1-2.el6" test_ref="oval:org.mitre.oval:tst:125362"/>
            <criterion comment="libxcb-devel is earlier than 0:1.9.1-2.el6" test_ref="oval:org.mitre.oval:tst:125376"/>
            <criterion comment="libxcb-doc is earlier than 0:1.9.1-2.el6" test_ref="oval:org.mitre.oval:tst:124975"/>
            <criterion comment="libxcb-python is earlier than 0:1.9.1-2.el6" test_ref="oval:org.mitre.oval:tst:125386"/>
            <criterion comment="xcb-proto is earlier than 0:1.8-3.el6" test_ref="oval:org.mitre.oval:tst:125329"/>
            <criterion comment="xkeyboard-config is earlier than 0:2.11-1.el6" test_ref="oval:org.mitre.oval:tst:125114"/>
            <criterion comment="xkeyboard-config-devel is earlier than 0:2.11-1.el6" test_ref="oval:org.mitre.oval:tst:125296"/>
            <criterion comment="xorg-x11-proto-devel is earlier than 0:7.7-9.el6" test_ref="oval:org.mitre.oval:tst:124962"/>
            <criterion comment="xorg-x11-xtrans-devel is earlier than 0:1.3.4-1.el6" test_ref="oval:org.mitre.oval:tst:125365"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libX11-debuginfo is earlier than 0:1.6.0-2.2.el6" test_ref="oval:org.mitre.oval:tst:138062"/>
            <criterion comment="libXcursor-debuginfo is earlier than 0:1.1.14-2.1.el6" test_ref="oval:org.mitre.oval:tst:138066"/>
            <criterion comment="libXext-debuginfo is earlier than 0:1.3.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:137467"/>
            <criterion comment="libXfixes-debuginfo is earlier than 0:5.0.1-2.1.el6" test_ref="oval:org.mitre.oval:tst:138151"/>
            <criterion comment="libXi-debuginfo is earlier than 0:1.7.2-2.2.el6" test_ref="oval:org.mitre.oval:tst:138395"/>
            <criterion comment="libXinerama-debuginfo is earlier than 0:1.1.3-2.1.el6" test_ref="oval:org.mitre.oval:tst:138236"/>
            <criterion comment="libXp-debuginfo is earlier than 0:1.0.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:138369"/>
            <criterion comment="libXrandr-debuginfo is earlier than 0:1.4.1-2.1.el6" test_ref="oval:org.mitre.oval:tst:138079"/>
            <criterion comment="libXrender-debuginfo is earlier than 0:0.9.8-2.1.el6" test_ref="oval:org.mitre.oval:tst:138238"/>
            <criterion comment="libXres-debuginfo is earlier than 0:1.0.7-2.1.el6" test_ref="oval:org.mitre.oval:tst:137832"/>
            <criterion comment="libXt-debuginfo is earlier than 0:1.1.4-6.1.el6" test_ref="oval:org.mitre.oval:tst:138234"/>
            <criterion comment="libXtst-debuginfo is earlier than 0:1.2.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:137884"/>
            <criterion comment="libXv-debuginfo is earlier than 0:1.0.9-2.1.el6" test_ref="oval:org.mitre.oval:tst:137961"/>
            <criterion comment="libXvMC-debuginfo is earlier than 0:1.0.8-2.1.el6" test_ref="oval:org.mitre.oval:tst:138225"/>
            <criterion comment="libXxf86dga-debuginfo is earlier than 0:1.1.4-2.1.el6" test_ref="oval:org.mitre.oval:tst:138286"/>
            <criterion comment="libXxf86vm-debuginfo is earlier than 0:1.1.3-2.1.el6" test_ref="oval:org.mitre.oval:tst:138102"/>
            <criterion comment="libdmx-debuginfo is earlier than 0:1.1.3-3.el6" test_ref="oval:org.mitre.oval:tst:137713"/>
            <criterion comment="libxcb-debuginfo is earlier than 0:1.9.1-2.el6" test_ref="oval:org.mitre.oval:tst:137944"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26725" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1307: nss security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 5</platform>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1307-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1307.html"/>
        <reference source="CESA-2014:1307" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-September/020595.html" ref_id="CESA-2014:1307"/>
        <reference source="CVE" ref_id="CVE-2014-1568" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1568.html"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A flaw was found in the way NSS parsed ASN.1 (Abstract Syntax Notation One)
input from certain RSA signatures. A remote attacker could use this flaw to
forge RSA certificates by providing a specially crafted signature to an
application using NSS. (CVE-2014-1568)

Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges Antoine Delignat-Lavaud and Intel Product Security
Incident Response Team as the original reporters.

All NSS users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, applications using NSS must be restarted for this update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:12.242-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:47.524-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:48.079-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26725 - CentOS checks added for RHEL vulnerabilities." date="2014-11-13T08:36:00.372-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-13T08:48:03.128-05:00">INTERIM</status_change>
            <status_change date="2014-12-01T04:00:41.246-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="nss-debuginfo is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:135359"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:123897"/>
            <criterion comment="nss-devel is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:123878"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:123032"/>
            <criterion comment="nss-tools is earlier than 0:3.16.1-4.el5_11" test_ref="oval:org.mitre.oval:tst:123944"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-util is earlier than 0:3.16.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:123805"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:123768"/>
            <criterion comment="nss is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:123826"/>
            <criterion comment="nss-devel is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:123832"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:123883"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:123201"/>
            <criterion comment="nss-tools is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:123954"/>
            <criterion comment="nss-softokn is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:123673"/>
            <criterion comment="nss-softokn-devel is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:123916"/>
            <criterion comment="nss-softokn-freebl is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:123871"/>
            <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:123968"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-debuginfo is earlier than 0:3.16.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:135234"/>
            <criterion comment="nss-softokn-debuginfo is earlier than 0:3.14.3-12.el6_5" test_ref="oval:org.mitre.oval:tst:135328"/>
            <criterion comment="nss-util-debuginfo is earlier than 0:3.16.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:135090"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 and CentOS Linux 7 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-softokn is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:124011"/>
            <criterion comment="nss-softokn-devel is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:123719"/>
            <criterion comment="nss-softokn-freebl is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:123982"/>
            <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:123896"/>
            <criterion comment="nss-util is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:123793"/>
            <criterion comment="nss-util-devel is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:123190"/>
            <criterion comment="nss is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:123492"/>
            <criterion comment="nss-devel is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:123873"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:123650"/>
            <criterion comment="nss-sysinit is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:123771"/>
            <criterion comment="nss-tools is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:123851"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 7 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-debuginfo is earlier than 0:3.16.2-7.el7_0" test_ref="oval:org.mitre.oval:tst:134839"/>
            <criterion comment="nss-softokn-debuginfo is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:135333"/>
            <criterion comment="nss-util-debuginfo is earlier than 0:3.16.2-2.el7_0" test_ref="oval:org.mitre.oval:tst:135339"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26700" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1148: squid security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1148-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1148.html"/>
        <reference source="CESA" ref_id="CESA-2014:1148"/>
        <reference source="CVE" ref_id="CVE-2013-4115" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4115.html"/>
        <reference source="CVE" ref_id="CVE-2014-3609" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3609.html"/>
        <description>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:03.508-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:04:00.287-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:25.516-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="squid is earlier than 7:2.6.STABLE21-7.el5_10" test_ref="oval:org.mitre.oval:tst:122890"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="squid is earlier than 7:3.1.10-22.el6_5" test_ref="oval:org.mitre.oval:tst:122939"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26695" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: RHSA-2013:1605 -- glibc security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1605.html" ref_id="RHSA-2013:1605"/>
        <reference source="CESA-2013:1605" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/000947.html" ref_id="CESA-2013:1605"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0242" ref_id="CVE-2013-0242"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1914" ref_id="CVE-2013-1914"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4332" ref_id="CVE-2013-4332"/>
        <description>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name Server
Caching Daemon (nscd) used by multiple programs on the system. Without
these libraries, the Linux system cannot function correctly.

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in glibc&amp;#39;s memory allocator functions (pvalloc, valloc, and
memalign). If an application used such a function, it could cause the
application to crash or, potentially, execute arbitrary code with the
privileges of the user running the application. (CVE-2013-4332)

A flaw was found in the regular expression matching routines that process
multibyte character input. If an application utilized the glibc regular
expression matching mechanism, an attacker could provide specially-crafted
input that, when processed, would cause the application to crash.
(CVE-2013-0242)

It was found that getaddrinfo() did not limit the amount of stack memory
used during name resolution. An attacker able to make an application
resolve an attacker-controlled hostname or IP address could possibly cause
the application to exhaust all stack memory and crash. (CVE-2013-1914)

Among other changes, this update includes an important fix for the following
bug:

* Due to a defect in the initial release of the getaddrinfo() system call in Red
Hat enterprise Linux 6.0, AF_INET and AF_INET6 queries resolved from the
/etc/hosts file returned queried names as canonical names. This incorrect
behavior is, however, still considered to be the expected behavior. As a result
of a recent change in getaddrinfo(), AF_INET6 queries started resolving the
canonical names correctly. However, this behavior was unexpected by applications
that relied on queries resolved from the /etc/hosts file, and these applications
could thus fail to operate properly. This update applies a fix ensuring that
AF_INET6 queries resolved from /etc/hosts always return the queried name as
canonical. Note that DNS lookups are resolved properly and always return the
correct canonical names. A proper fix to AF_INET6 queries resolution from
/etc/hosts may be applied in future releases; for now, due to a lack of
standard, Red Hat suggests the first entry in the /etc/hosts file, that applies
for the IP address being resolved, to be considered the canonical entry.
(BZ#1022022)

These updated glibc packages also include additional bug fixes and 
various enhancements. Space precludes documenting all of these changes 
in this advisory. Users are directed to the Red Hat Enterprise Linux 6.5 
Technical Notes, linked to in the References, for information on the 
most significant of these changes.

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:15:47">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:49.469-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:00:44.139-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:21.462-05:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-11T18:33:17.686-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T18:33:17.686-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:126086"/>
            <criterion comment="glibc-common is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:125878"/>
            <criterion comment="glibc-devel is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:126106"/>
            <criterion comment="glibc-headers is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:125632"/>
            <criterion comment="glibc-static is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:125781"/>
            <criterion comment="glibc-utils is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:125748"/>
            <criterion comment="nscd is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:125691"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc-debuginfo is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:125137"/>
            <criterion comment="glibc-debuginfo-common is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:125344"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26690" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1173: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1173-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1173.html"/>
        <reference source="CVE" ref_id="CVE-2014-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0547.html"/>
        <reference source="CVE" ref_id="CVE-2014-0548" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0548.html"/>
        <reference source="CVE" ref_id="CVE-2014-0549" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0549.html"/>
        <reference source="CVE" ref_id="CVE-2014-0550" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0550.html"/>
        <reference source="CVE" ref_id="CVE-2014-0551" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0551.html"/>
        <reference source="CVE" ref_id="CVE-2014-0552" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0552.html"/>
        <reference source="CVE" ref_id="CVE-2014-0553" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0553.html"/>
        <reference source="CVE" ref_id="CVE-2014-0554" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0554.html"/>
        <reference source="CVE" ref_id="CVE-2014-0555" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0555.html"/>
        <reference source="CVE" ref_id="CVE-2014-0556" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0556.html"/>
        <reference source="CVE" ref_id="CVE-2014-0557" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0557.html"/>
        <reference source="CVE" ref_id="CVE-2014-0559" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0559.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-21,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551,
CVE-2014-0552, CVE-2014-0553, CVE-2014-0554, CVE-2014-0555, CVE-2014-0556,
CVE-2014-0557, CVE-2014-0559)

A flaw in flash-plugin could allow an attacker to bypass the same-origin
policy. (CVE-2014-0548)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.406.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:02.237-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:45.315-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:43.064-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.406-1.el5" test_ref="oval:org.mitre.oval:tst:123869"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.406-1.el6" test_ref="oval:org.mitre.oval:tst:123356"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26667" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1075: qemu-kvm security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1075-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1075.html"/>
        <reference source="CESA" ref_id="CESA-2014:1075"/>
        <reference source="CVE" ref_id="CVE-2014-0222" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0222.html"/>
        <reference source="CVE" ref_id="CVE-2014-0223" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0223.html"/>
        <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:09.386-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:55.706-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:19.794-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.14" test_ref="oval:org.mitre.oval:tst:122675"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.14" test_ref="oval:org.mitre.oval:tst:122690"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.14" test_ref="oval:org.mitre.oval:tst:123036"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.14" test_ref="oval:org.mitre.oval:tst:122814"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26652" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1635 -- pacemaker security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>pacemaker</product>
        </affected>
        <reference source="VENDOR" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1635.html" ref_id="RHSA-2013:1635"/>
        <reference source="CESA-2013:1635" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2013-November/001037.html" ref_id="CESA-2013:1635"/>
        <reference source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0281" ref_id="CVE-2013-0281"/>
        <description><![CDATA[Pacemaker is a high-availability cluster resource manager with a powerful
policy engine.

A denial of service flaw was found in the way Pacemaker performed
authentication and processing of remote connections in certain
circumstances. When Pacemaker was configured to allow remote Cluster
Information Base (CIB) configuration or resource management, a remote
attacker could use this flaw to cause Pacemaker to block indefinitely
(preventing it from serving other requests). (CVE-2013-0281)

Note: The default Pacemaker configuration in Red Hat Enterprise Linux 6 has
the remote CIB management functionality disabled.

The pacemaker package has been upgraded to upstream version 1.1.10, which
provides a number of bug fixes and enhancements over the previous version:

* Pacemaker no longer assumes unknown cman nodes are safely stopped.

* The core dump file now converts all exit codes into positive &#39;errno&#39;
values.

* Pacemaker ensures a return to a stable state after too many fencing
failures, and initiates a shutdown if a node claimed to be fenced is still
active.

* The crm_error tool adds the ability to list and print error symbols.

* The crm_resource command allows individual resources to be reprobed, and
implements the &quot;--ban&quot; option for moving resources away from nodes.
The &quot;--clear&quot; option has replaced the &quot;--unmove&quot; option. Also, crm_resource
now supports OCF tracing when using the &quot;--force&quot; option.

* The IPC mechanism restores the ability for members of the haclient group
to connect to the cluster.

* The Policy Engine daemon allows active nodes in the current membership to
be fenced without quorum.

* Policy Engine now suppresses meaningless IDs when displaying anonymous
clone status, supports maintenance mode for a single node, and correctly
handles the recovered resources before they are operated on.

* XML configuration files are now checked for non-printing characters and
replaced with their octal equivalent when exporting XML text. Also, a more
reliable buffer allocation strategy has been implemented to prevent
lockups.

(BZ#987355)

Additional bug fixes:

* The &quot;crm_resource --move&quot; command was designed for atomic resources and
could not handle resources on clones, masters, or slaves present on
multiple nodes. Consequently, crm_resource could not obtain enough
information to move a resource and did not perform any action. The &quot;--ban&quot;
and &quot;--clear&quot; options have been added to allow the administrator to
instruct the cluster unambiguously. Clone, master, and slave resources can
now be navigated within the cluster as expected. (BZ#902407)

* The hacluster user account did not have a user identification (UID) or
group identification (GID) number reserved on the system. Thus, UID and GID
values were picked randomly during the installation process. The UID and
GID number 189 was reserved for hacluster and is now used consistently for
all installations. (BZ#908450)

* Certain clusters used node host names that did not match the output of
the &quot;uname -n&quot; command. Thus, the default node name used by the crm_standby
and crm_failcount commands was incorrect and caused the cluster to ignore
the update by the administrator. The crm_node command is now used instead
of the uname utility in helper scripts. As a result, the cluster behaves as
expected. (BZ#913093)

* Due to incorrect return code handling, internal recovery logic of the
crm_mon utility was not executed when a configuration updated failed to
apply, leading to an assertion failure. Return codes are now checked
correctly, and the recovery of an expected error state is now handled
transparently. (BZ#951371)

* cman&#39;s automatic unfencing feature failed when combined with Pacemaker.
Support for automated unfencing in Pacemaker has been added, and the
unwanted behavior no longer occurs. (BZ#996850)

All pacemaker users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-28T18:15:41">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-29T12:47:51.526-04:00">DRAFT</status_change>
            <status_change date="2014-11-17T04:00:42.401-05:00">INTERIM</status_change>
            <status_change date="2014-12-08T04:00:20.978-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="pacemaker-debuginfo is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:125891"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criterion comment="pacemaker-remote is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:125581"/>
        </criteria>
        <criteria comment="CentOS Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pacemaker is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:125758"/>
            <criterion comment="pacemaker-cli is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:125991"/>
            <criterion comment="pacemaker-cluster-libs is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:126043"/>
            <criterion comment="pacemaker-cts is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:125912"/>
            <criterion comment="pacemaker-doc is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:125397"/>
            <criterion comment="pacemaker-libs is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:126048"/>
            <criterion comment="pacemaker-libs-devel is earlier than 0:1.1.10-14.el6" test_ref="oval:org.mitre.oval:tst:125701"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26646" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1059: libvirt bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1059-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1059.html"/>
        <description>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In addition,
libvirt provides tools for remote management of virtualized systems. 

This update fixes the following bugs:

* Previously, the libvirt API did not properly cancel the migration of QEMU
domains if it detected an error, which caused QEMU to pause guest CPUs. With
this update, if libvirt detects an error during a migration process, it informs
QEMU to cancel the ongoing migration. Now, after a failed migration, libvirt
resumes a domain, which then remains running, and QEMU no longer pauses guest
CPUs. (BZ#1100642)

* Prior to this update, the libvirt API canceled migration when it could not
access a QEMU monitor for more that 30 seconds to get migration status.
Consequently, when the libvirt user queried some data from QEMU during an
ongoing migration, the query timed out and libvirt canceled the migration. As a
workaround, ignore the time-out error and try querying again as libvirt checks
for migration status every 50ms. As a result, migration in a Red Hat Enterprise
Virtualization environment is no longer canceled when QEMU is slow to respond.
(BZ#1100671)

* Previously, a host device located on a PCI bus with a domain other than "0"
could not be assigned to a virtual guest using PCI passthrough. This bug has
been fixed, and QEMU is now able to assign non-0 domains in the PCI address. As
a result, host devices located on a PCI bus with a non-0 domain can now be
assigned to a guest as intended. (BZ#1100737)

Users of libvirt are advised to upgrade to these updated packages, which fix
these bugs. After installing the updated packages, libvirtd will be restarted
automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:08.284-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:43.974-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:41.223-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt is earlier than 0:0.10.2-29.el6_5.11" test_ref="oval:org.mitre.oval:tst:123844"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.11" test_ref="oval:org.mitre.oval:tst:123675"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.11" test_ref="oval:org.mitre.oval:tst:123569"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.11" test_ref="oval:org.mitre.oval:tst:123423"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.11" test_ref="oval:org.mitre.oval:tst:123783"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26605" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1391: glibc security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1391-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1391.html"/>
        <reference source="CVE" ref_id="CVE-2013-4237" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4237.html"/>
        <reference source="CVE" ref_id="CVE-2013-4458" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4458.html"/>
        <reference source="CESA-2014:1391" ref_id="CESA-2014:1391" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001187.html"/>
        <description>The glibc packages provide the standard C libraries (libc), POSIX thread
libraries (libpthread), standard math libraries (libm), and the Name
Server Caching Daemon (nscd) used by multiple programs on the system.
Without these libraries, the Linux system cannot function correctly.

An out-of-bounds write flaw was found in the way the glibc's readdir_r()
function handled file system entries longer than the NAME_MAX character
constant. A remote attacker could provide a specially crafted NTFS or CIFS
file system that, when processed by an application using readdir_r(), would
cause that application to crash or, potentially, allow the attacker to
execute arbitrary code with the privileges of the user running the
application. (CVE-2013-4237)

It was found that getaddrinfo() did not limit the amount of stack memory
used during name resolution. An attacker able to make an application
resolve an attacker-controlled hostname or IP address could possibly cause
the application to exhaust all stack memory and crash. (CVE-2013-4458)

These updated glibc packages also include several bug fixes and two
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.6 Technical
Notes, linked to in the References section, for information on the most
significant of these changes.

All glibc users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:32.647-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:14.217-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:36.427-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26605 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:50.946-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:09.068-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:125145"/>
            <criterion comment="glibc-common is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:125232"/>
            <criterion comment="glibc-devel is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:125135"/>
            <criterion comment="glibc-headers is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:125086"/>
            <criterion comment="glibc-static is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:125182"/>
            <criterion comment="glibc-utils is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:125139"/>
            <criterion comment="nscd is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:124988"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="glibc-debuginfo is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:138389"/>
            <criterion comment="glibc-debuginfo-common is earlier than 0:2.12-1.149.el6" test_ref="oval:org.mitre.oval:tst:138284"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26589" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1306: bash security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1306-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1306.html"/>
        <reference source="CESA" ref_id="CESA-2014:1306"/>
        <reference source="CVE" ref_id="CVE-2014-7169" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-7169.html"/>
        <description>The GNU Bourne Again shell (Bash) is a shell and command language
interpreter compatible with the Bourne shell (sh). Bash is the default
shell for Red Hat Enterprise Linux.

It was found that the fix for CVE-2014-6271 was incomplete, and Bash still
allowed certain characters to be injected into other environments via
specially crafted environment variables. An attacker could potentially use
this flaw to override or bypass environment restrictions to execute shell
commands. Certain services and applications allow remote unauthenticated
attackers to provide environment variables, allowing them to exploit this
issue. (CVE-2014-7169)

Applications which directly create bash functions as environment variables
need to be made aware of changes to the way names are handled by this
update. For more information see the Knowledgebase article at
https://access.redhat.com/articles/1200223

Note: Docker users are advised to use "yum update" within their containers,
and to commit the resulting changes.

For additional information on CVE-2014-6271 and CVE-2014-7169, refer to the
aforementioned Knowledgebase article.

All bash users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:04.676-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:41.186-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:36.282-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bash is earlier than 0:4.1.2-15.el6_5.2" test_ref="oval:org.mitre.oval:tst:123544"/>
            <criterion comment="bash-doc is earlier than 0:4.1.2-15.el6_5.2" test_ref="oval:org.mitre.oval:tst:123461"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="bash is earlier than 0:3.2-33.el5_11.4" test_ref="oval:org.mitre.oval:tst:123086"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="bash is earlier than 0:3.2-33.el5_10.4" test_ref="oval:org.mitre.oval:tst:123949"/>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bash is earlier than 0:4.2.45-5.el7_0.4" test_ref="oval:org.mitre.oval:tst:123527"/>
            <criterion comment="bash-doc is earlier than 0:4.2.45-5.el7_0.4" test_ref="oval:org.mitre.oval:tst:123900"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26573" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1144: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1144-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1144.html"/>
        <reference source="CESA" ref_id="CESA-2014:1144"/>
        <reference source="CVE" ref_id="CVE-2014-1562" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1562.html"/>
        <reference source="CVE" ref_id="CVE-2014-1567" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1567.html"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:04.763-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:46.744-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:01:04.557-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.8.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:122510"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.8.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:123047"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="firefox is earlier than 0:24.8.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:122594"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.8.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:123084"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 7 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.8.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:122819"/>
            <criterion comment="xulrunner is earlier than 0:24.8.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:122875"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.8.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:122877"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 7 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.8.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:122891"/>
            <criterion comment="xulrunner is earlier than 0:24.8.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:122772"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.8.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:123170"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26526" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1145: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1145-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1145.html"/>
        <reference source="CESA" ref_id="CESA-2014:1145"/>
        <reference source="CVE" ref_id="CVE-2014-1562" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1562.html"/>
        <reference source="CVE" ref_id="CVE-2014-1567" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1567.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:05.497-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:43.842-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:58.898-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.8.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:122759"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.8.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:123029"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:24.8.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:123152"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.8.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:122969"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26521" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1293: bash security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>bash</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1293-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1293.html"/>
        <reference source="CESA" ref_id="CESA-2014:1293"/>
        <reference source="CVE" ref_id="CVE-2014-6271" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-6271.html"/>
        <description>The GNU Bourne Again shell (Bash) is a shell and command language
interpreter compatible with the Bourne shell (sh). Bash is the default
shell for Red Hat Enterprise Linux.

A flaw was found in the way Bash evaluated certain specially crafted
environment variables. An attacker could use this flaw to override or
bypass environment restrictions to execute shell commands. Certain
services and applications allow remote unauthenticated attackers to
provide environment variables, allowing them to exploit this issue.
(CVE-2014-6271)

For additional information on the CVE-2014-6271 flaw, refer to the
Knowledgebase article at https://access.redhat.com/articles/1200223

Red Hat would like to thank Stephane Chazelas for reporting this issue.

All bash users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:13.020-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:36.830-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:30.329-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bash is earlier than 0:4.1.2-15.el6_5.1" test_ref="oval:org.mitre.oval:tst:123932"/>
            <criterion comment="bash-doc is earlier than 0:4.1.2-15.el6_5.1" test_ref="oval:org.mitre.oval:tst:123696"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="bash is earlier than 0:3.2-33.el5.1" test_ref="oval:org.mitre.oval:tst:123953"/>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bash is earlier than 0:4.2.45-5.el7_0.2" test_ref="oval:org.mitre.oval:tst:123926"/>
            <criterion comment="bash-doc is earlier than 0:4.2.45-5.el7_0.2" test_ref="oval:org.mitre.oval:tst:123825"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26499" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1166: jakarta-commons-httpclient security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1166-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1166.html"/>
        <reference source="CESA" ref_id="CESA-2014:1166"/>
        <reference source="CVE" ref_id="CVE-2014-3577" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3577.html"/>
        <description>Jakarta Commons HTTPClient implements the client side of HTTP standards.

It was discovered that the HTTPClient incorrectly extracted host name from
an X.509 certificate subject's Common Name (CN) field. A man-in-the-middle
attacker could use this flaw to spoof an SSL server using a specially
crafted X.509 certificate. (CVE-2014-3577)

For additional information on this flaw, refer to the Knowledgebase
article in the References section.

All jakarta-commons-httpclient users are advised to upgrade to these
updated packages, which contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:06.564-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:34.668-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:29.562-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:123818"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:123708"/>
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:123816"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.0-7jpp.4.el5_10" test_ref="oval:org.mitre.oval:tst:123791"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:123167"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:123604"/>
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:122896"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-0.9.el6_5" test_ref="oval:org.mitre.oval:tst:123758"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:123792"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:123283"/>
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:123770"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-16.el7_0" test_ref="oval:org.mitre.oval:tst:123817"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26477" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1172: procmail security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>procmail</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1172-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1172.html"/>
        <reference source="CESA" ref_id="CESA-2014:1172"/>
        <reference source="CVE" ref_id="CVE-2014-3618" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3618.html"/>
        <description>The procmail program is used for local mail delivery. In addition to just
delivering mail, procmail can be used for automatic filtering, presorting,
and other mail handling jobs.

A heap-based buffer overflow flaw was found in procmail's formail utility.
A remote attacker could send an email with specially crafted headers that,
when processed by formail, could cause procmail to crash or, possibly,
execute arbitrary code as the user running formail. (CVE-2014-3618)

All procmail users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-26T11:25:02">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-29T12:07:01.562-04:00">DRAFT</status_change>
            <status_change date="2014-10-20T04:00:33.283-04:00">INTERIM</status_change>
            <status_change date="2014-11-10T04:01:27.293-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="procmail is earlier than 0:3.22-17.1.2" test_ref="oval:org.mitre.oval:tst:123250"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="procmail is earlier than 0:3.22-17.1.2.el5_10" test_ref="oval:org.mitre.oval:tst:123831"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="procmail is earlier than 0:3.22-25.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:123631"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="procmail is earlier than 0:3.22-34.el7_0.1" test_ref="oval:org.mitre.oval:tst:123381"/>
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26426" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1052: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1052-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1052.html"/>
        <reference source="CESA" ref_id="CESA-2014:1052"/>
        <reference source="CVE" ref_id="CVE-2014-3505" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3505.html"/>
        <reference source="CVE" ref_id="CVE-2014-3506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3506.html"/>
        <reference source="CVE" ref_id="CVE-2014-3507" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3507.html"/>
        <reference source="CVE" ref_id="CVE-2014-3508" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3508.html"/>
        <reference source="CVE" ref_id="CVE-2014-3509" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3509.html"/>
        <reference source="CVE" ref_id="CVE-2014-3510" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3510.html"/>
        <reference source="CVE" ref_id="CVE-2014-3511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3511.html"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL),
Transport Layer Security (TLS), and Datagram Transport Layer Security
(DTLS) protocols, as well as a full-strength, general purpose cryptography
library.

A race condition was found in the way OpenSSL handled ServerHello messages
with an included Supported EC Point Format extension. A malicious server
could possibly use this flaw to cause a multi-threaded TLS/SSL client using
OpenSSL to write into freed memory, causing the client to crash or execute
arbitrary code. (CVE-2014-3509)

It was discovered that the OBJ_obj2txt() function could fail to properly
NUL-terminate its output. This could possibly cause an application using
OpenSSL functions to format fields of X.509 certificates to disclose
portions of its memory. (CVE-2014-3508)

A flaw was found in the way OpenSSL handled fragmented handshake packets.
A man-in-the-middle attacker could use this flaw to force a TLS/SSL server
using OpenSSL to use TLS 1.0, even if both the client and the server
supported newer protocol versions. (CVE-2014-3511)

Multiple flaws were discovered in the way OpenSSL handled DTLS packets.
A remote attacker could use these flaws to cause a DTLS server or client
using OpenSSL to crash or use excessive amounts of memory. (CVE-2014-3505,
CVE-2014-3506, CVE-2014-3507)

A NULL pointer dereference flaw was found in the way OpenSSL performed a
handshake when using the anonymous Diffie-Hellman (DH) key exchange. A
malicious server could cause a DTLS client using OpenSSL to crash if that
client had anonymous DH cipher suites enabled. (CVE-2014-3510)

All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:49.893-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:55.061-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:37.131-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.15" test_ref="oval:org.mitre.oval:tst:122547"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.15" test_ref="oval:org.mitre.oval:tst:122626"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.15" test_ref="oval:org.mitre.oval:tst:122570"/>
            <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.15" test_ref="oval:org.mitre.oval:tst:122703"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl is earlier than 1:1.0.1e-34.el7_0.4" test_ref="oval:org.mitre.oval:tst:122367"/>
            <criterion comment="openssl-devel is earlier than 1:1.0.1e-34.el7_0.4" test_ref="oval:org.mitre.oval:tst:122537"/>
            <criterion comment="openssl-libs is earlier than 1:1.0.1e-34.el7_0.4" test_ref="oval:org.mitre.oval:tst:122648"/>
            <criterion comment="openssl-perl is earlier than 1:1.0.1e-34.el7_0.4" test_ref="oval:org.mitre.oval:tst:122686"/>
            <criterion comment="openssl-static is earlier than 1:1.0.1e-34.el7_0.4" test_ref="oval:org.mitre.oval:tst:122485"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26407" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1033: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1033-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1033.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4227" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4227.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4265" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4265.html"/>
        <description>IBM Java SE version 6 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-4209, CVE-2014-4218,
CVE-2014-4219, CVE-2014-4227, CVE-2014-4244, CVE-2014-4252, CVE-2014-4262,
CVE-2014-4263, CVE-2014-4265)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 6 SR16-FP1 release. All running
instances of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:57.508-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:52.898-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:35.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122517"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122462"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122541"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:121689"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122553"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122398"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122234"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122498"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:121990"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122651"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122357"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122617"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:121901"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122289"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122592"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26406" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1031: 389-ds-base security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1031-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1031.html"/>
        <reference source="CESA" ref_id="CESA-2014:1031"/>
        <reference source="CVE" ref_id="CVE-2014-3562" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3562.html"/>
        <description>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

It was found that when replication was enabled for each attribute in 389
Directory Server, which is the default configuration, the server returned
replicated metadata when the directory was searched while debugging was
enabled. A remote attacker could use this flaw to disclose potentially
sensitive information. (CVE-2014-3562)

This issue was discovered by Ludwig Krispenz of Red Hat.

All 389-ds-base users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the 389 server service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:54.165-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:52.721-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:34.833-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="389-ds-base is earlier than 0:1.2.11.15-34.el6_5" test_ref="oval:org.mitre.oval:tst:122516"/>
            <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-34.el6_5" test_ref="oval:org.mitre.oval:tst:122486"/>
            <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-34.el6_5" test_ref="oval:org.mitre.oval:tst:122226"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="389-ds-base is earlier than 0:1.3.1.6-26.el7_0" test_ref="oval:org.mitre.oval:tst:122506"/>
            <criterion comment="389-ds-base-devel is earlier than 0:1.3.1.6-26.el7_0" test_ref="oval:org.mitre.oval:tst:122405"/>
            <criterion comment="389-ds-base-libs is earlier than 0:1.3.1.6-26.el7_0" test_ref="oval:org.mitre.oval:tst:121859"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26390" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:1390: luci security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>luci</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1390-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1390.html"/>
        <reference source="CVE" ref_id="CVE-2014-3593" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3593.html"/>
        <reference source="CESA-2014:1390" ref_id="CESA-2014:1390" ref_url="http://lists.centos.org/pipermail/centos-cr-announce/2014-October/001283.html"/>
        <description>Luci is a web-based high availability administration application.

It was discovered that luci used eval() on inputs containing strings from
the cluster configuration file when generating its web pages. An attacker
with privileges to create or edit the cluster configuration could use this
flaw to execute arbitrary code as the luci user on a host running luci.
(CVE-2014-3593)

This issue was discovered by Jan PokornГЅ of Red Hat.

These updated luci packages also include several bug fixes and multiple
enhancements. Space precludes documenting all of these changes in this
advisory. Users are directed to the Red Hat Enterprise Linux 6.6 Technical
Notes, linked to in the References section, for information on the most
significant of these changes.

All luci users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add these
enhancements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:18.377-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:11.197-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:19.778-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26390 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:52.637-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:08.323-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <criterion comment="luci is earlier than 0:0.26.0-63.el6" test_ref="oval:org.mitre.oval:tst:124900"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria comment="CentOS Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criterion comment="luci is earlier than 0:0.26.0-63.el6.centos" test_ref="oval:org.mitre.oval:tst:137992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26388" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1110: glibc security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1110-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1110.html"/>
        <reference source="CESA" ref_id="CESA-2014:1110"/>
        <reference source="CVE" ref_id="CVE-2014-0475" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0475.html"/>
        <reference source="CVE" ref_id="CVE-2014-5119" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-5119.html"/>
        <description>The glibc packages contain the standard C libraries used by multiple
programs on the system. These packages contain the standard C and the
standard math libraries. Without these two libraries, a Linux system cannot
function properly.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-09-08T16:42:29">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-17T10:44:08.573-04:00">DRAFT</status_change>
            <status_change date="2014-10-06T04:03:35.745-04:00">INTERIM</status_change>
            <status_change date="2014-10-27T04:00:45.093-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="glibc is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:122956"/>
            <criterion comment="glibc-common is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:122380"/>
            <criterion comment="glibc-devel is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:123024"/>
            <criterion comment="glibc-headers is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:123069"/>
            <criterion comment="glibc-utils is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:122669"/>
            <criterion comment="nscd is earlier than 0:2.5-118.el5_10.3" test_ref="oval:org.mitre.oval:tst:123071"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="glibc is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:122887"/>
            <criterion comment="glibc-common is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:122739"/>
            <criterion comment="glibc-devel is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:123068"/>
            <criterion comment="glibc-headers is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:123073"/>
            <criterion comment="glibc-static is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:122402"/>
            <criterion comment="glibc-utils is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:122779"/>
            <criterion comment="nscd is earlier than 0:2.12-1.132.el6_5.4" test_ref="oval:org.mitre.oval:tst:122909"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="glibc is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:123035"/>
            <criterion comment="glibc-common is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:122535"/>
            <criterion comment="glibc-devel is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:123059"/>
            <criterion comment="glibc-headers is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:122432"/>
            <criterion comment="glibc-static is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:123014"/>
            <criterion comment="glibc-utils is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:122938"/>
            <criterion comment="nscd is earlier than 0:2.17-55.el7_0.1" test_ref="oval:org.mitre.oval:tst:123079"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26375" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1051: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1051-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1051.html"/>
        <reference source="CVE" ref_id="CVE-2014-0538" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0538.html"/>
        <reference source="CVE" ref_id="CVE-2014-0540" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0540.html"/>
        <reference source="CVE" ref_id="CVE-2014-0541" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0541.html"/>
        <reference source="CVE" ref_id="CVE-2014-0542" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0542.html"/>
        <reference source="CVE" ref_id="CVE-2014-0543" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0543.html"/>
        <reference source="CVE" ref_id="CVE-2014-0544" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0544.html"/>
        <reference source="CVE" ref_id="CVE-2014-0545" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0545.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-18,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0538, CVE-2014-0540, CVE-2014-0541, CVE-2014-0542, 
CVE-2014-0543, CVE-2014-0544, CVE-2014-0545)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.400.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:43.573-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:50.047-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:32.651-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.400-1.el5" test_ref="oval:org.mitre.oval:tst:121704"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.400-1.el6" test_ref="oval:org.mitre.oval:tst:122600"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26374" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1038: tomcat6 security update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1038-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1038.html"/>
        <reference source="CESA" ref_id="CESA-2014:1038"/>
        <reference source="CVE" ref_id="CVE-2013-4590" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4590.html"/>
        <reference source="CVE" ref_id="CVE-2014-0119" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0119.html"/>
        <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that several application-provided XML files, such as web.xml,
content.xml, *.tld, *.tagx, and *.jspx, resolved external entities,
permitting XML External Entity (XXE) attacks. An attacker able to deploy
malicious applications to Tomcat could use this flaw to circumvent security
restrictions set by the JSM, and gain access to sensitive information on
the system. Note that this flaw only affected deployments in which Tomcat
is running applications from untrusted sources, such as in a shared hosting
environment. (CVE-2013-4590)

It was found that, in certain circumstances, it was possible for a
malicious web application to replace the XML parsers used by Apache Tomcat
to process XSLTs for the default servlet, JSP documents, tag library
descriptors (TLDs), and tag plug-in configuration files. The injected XML
parser(s) could then bypass the limits imposed on XML external entities
and/or gain access to the XML files processed for other web applications
deployed on the same Apache Tomcat instance. (CVE-2014-0119)

All Tomcat users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:45.819-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:49.836-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:32.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat6 is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:122650"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:122501"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:122327"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:122586"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:122562"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:122520"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:122470"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:122649"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-78.el6_5" test_ref="oval:org.mitre.oval:tst:122556"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26370" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1036: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1036-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1036.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <description>IBM J2SE version 5.0 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-4209, CVE-2014-4218,
CVE-2014-4219, CVE-2014-4244, CVE-2014-4252, CVE-2014-4262, CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM J2SE 5.0 SR16-FP7 release. All running
instances of IBM Java must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:47.103-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:49.235-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:31.718-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122123"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122509"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122656"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122192"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:121907"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122671"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122596"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122687"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122607"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:121790"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122552"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122629"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122566"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122347"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122275"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26357" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1009: samba4 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1009-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1009.html"/>
        <reference source="CESA" ref_id="CESA-2014:1009"/>
        <reference source="CVE" ref_id="CVE-2014-0178" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0178.html"/>
        <reference source="CVE" ref_id="CVE-2014-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0244.html"/>
        <reference source="CVE" ref_id="CVE-2014-3493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3493.html"/>
        <reference source="CVE" ref_id="CVE-2014-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3560.html"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A heap-based buffer overflow flaw was found in Samba's NetBIOS message
block daemon (nmbd). An attacker on the local network could use this flaw
to send specially crafted packets that, when processed by nmbd, could
possibly lead to arbitrary code execution with root privileges.
(CVE-2014-3560)

All Samba users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:44.637-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:48.708-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:30.968-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="samba4 is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:122288"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:122456"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:122311"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:121933"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:121984"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:122296"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:122317"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:122447"/>
          <criterion comment="samba4-python is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:122142"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:122214"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:122245"/>
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:121983"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:121777"/>
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-63.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:121966"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26314" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1012: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1012-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1012.html"/>
        <reference source="CESA" ref_id="CESA-2014:1012"/>
        <reference source="CVE" ref_id="CVE-2012-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-6712" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6712.html"/>
        <reference source="CVE" ref_id="CVE-2014-0237" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0237.html"/>
        <reference source="CVE" ref_id="CVE-2014-0238" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0238.html"/>
        <reference source="CVE" ref_id="CVE-2014-1943" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1943.html"/>
        <reference source="CVE" ref_id="CVE-2014-2270" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2270.html"/>
        <reference source="CVE" ref_id="CVE-2014-3479" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3479.html"/>
        <reference source="CVE" ref_id="CVE-2014-3480" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3480.html"/>
        <reference source="CVE" ref_id="CVE-2014-3515" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3515.html"/>
        <reference source="CVE" ref_id="CVE-2014-4049" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4049.html"/>
        <reference source="CVE" ref_id="CVE-2014-4721" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4721.html"/>
        <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Server. PHP's fileinfo module provides functions used to identify a
particular file according to the type of data contained by the file.

Multiple denial of service flaws were found in the way the File Information
(fileinfo) extension parsed certain Composite Document Format (CDF) files.
A remote attacker could use either of these flaws to crash a PHP
application using fileinfo via a specially crafted CDF file.
(CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, CVE-2014-3480, CVE-2012-1571)

Two denial of service flaws were found in the way the File Information
(fileinfo) extension handled indirect and search rules. A remote attacker
could use either of these flaws to cause a PHP application using fileinfo
to crash or consume an excessive amount of CPU. (CVE-2014-1943,
CVE-2014-2270)

A heap-based buffer overflow flaw was found in the way PHP parsed DNS TXT
records. A malicious DNS server or a man-in-the-middle attacker could
possibly use this flaw to execute arbitrary code as the PHP interpreter if
a PHP application used the dns_get_record() function to perform a DNS
query. (CVE-2014-4049)

A type confusion issue was found in PHP's phpinfo() function. A malicious
script author could possibly use this flaw to disclose certain portions of
server memory. (CVE-2014-4721)

A buffer over-read flaw was found in the way the DateInterval class parsed
interval specifications. An attacker able to make a PHP application parse a
specially crafted specification using DateInterval could possibly cause the
PHP interpreter to crash. (CVE-2013-6712)

A type confusion issue was found in the SPL ArrayObject and
SPLObjectStorage classes' unserialize() method. A remote attacker able to
submit specially crafted input to a PHP application, which would then
unserialize this input using one of the aforementioned methods, could use
this flaw to execute arbitrary code with the privileges of the user running
that PHP application. (CVE-2014-3515)

The CVE-2014-0237, CVE-2014-0238, CVE-2014-3479, and CVE-2014-3480 issues
were discovered by Francisco Alonso of Red Hat Product Security.

All php53 and php users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:51.902-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:44.886-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:27.250-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php53 is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121848"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122422"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121506"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122213"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122442"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122364"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122385"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122085"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122300"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122383"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122205"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122090"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122243"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121820"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122302"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122386"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121844"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122063"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121863"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:122138"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-23.el5_10" test_ref="oval:org.mitre.oval:tst:121502"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122144"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122521"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122240"/>
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122396"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122067"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122020"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:121691"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122483"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122529"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:121529"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122491"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122469"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122293"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122353"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:121951"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122239"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:121534"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122478"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122446"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122000"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122382"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122231"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122423"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:121548"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122450"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122373"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5.1" test_ref="oval:org.mitre.oval:tst:122355"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26272" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1674: dracut security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>dracut</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1674-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1674.html"/>
        <reference source="CVE" ref_id="CVE-2012-4453" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4453.html"/>
        <description>dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T08:31:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:28.643-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:46.289-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:52.512-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dracut is earlier than 0:004-336.el6" test_ref="oval:org.mitre.oval:tst:120859"/>
          <criterion comment="dracut-caps is earlier than 0:004-336.el6" test_ref="oval:org.mitre.oval:tst:121129"/>
          <criterion comment="dracut-fips is earlier than 0:004-336.el6" test_ref="oval:org.mitre.oval:tst:121261"/>
          <criterion comment="dracut-fips-aesni is earlier than 0:004-336.el6" test_ref="oval:org.mitre.oval:tst:121357"/>
          <criterion comment="dracut-generic is earlier than 0:004-336.el6" test_ref="oval:org.mitre.oval:tst:121445"/>
          <criterion comment="dracut-kernel is earlier than 0:004-336.el6" test_ref="oval:org.mitre.oval:tst:121314"/>
          <criterion comment="dracut-network is earlier than 0:004-336.el6" test_ref="oval:org.mitre.oval:tst:121027"/>
          <criterion comment="dracut-tools is earlier than 0:004-336.el6" test_ref="oval:org.mitre.oval:tst:121336"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26244" version="5" class="patch">
      <metadata>
        <title>RHSA-2013-1605: glibc security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1605-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1605.html"/>
        <reference source="CESA" ref_id="CESA-2013:1605"/>
        <reference source="CVE" ref_id="CVE-2013-0242" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0242.html"/>
        <reference source="CVE" ref_id="CVE-2013-1914" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1914.html"/>
        <reference source="CVE" ref_id="CVE-2013-4332" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4332.html"/>
        <description>Updated glibc packages that fix three security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T08:31:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:30.504-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:42.316-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:49.876-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26244 - Corrected two references on RHSA advisory with mistype in ref_id" date="2015-02-16T13:01:00.980-05:00">
              <contributor organization="Positive Technologies">Alexander Leonov</contributor>
            </modified>
            <status_change date="2015-02-16T13:05:05.492-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:21.601-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-utils is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:121335"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:120736"/>
          <criterion comment="glibc is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:121418"/>
          <criterion comment="nscd is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:121079"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:121239"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:121453"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.132.el6" test_ref="oval:org.mitre.oval:tst:121434"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26241" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1732: busybox security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>busybox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1732-03" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1732.html"/>
        <reference source="CESA" ref_id="CESA-2013:1732"/>
        <reference source="CVE" ref_id="CVE-2013-1813" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1813.html"/>
        <description>util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:28.140-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:41.914-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:49.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="busybox-petitboot is earlier than 1:1.15.1-20.el6" test_ref="oval:org.mitre.oval:tst:121425"/>
          <criterion comment="busybox is earlier than 1:1.15.1-20.el6" test_ref="oval:org.mitre.oval:tst:121374"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26218" version="5" class="patch">
      <metadata>
        <title>RHSA-2012:0884: openssh security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1591-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1591.html"/>
        <reference source="CESA" ref_id="CESA-2013:1591"/>
        <reference source="CVE" ref_id="CVE-2010-5107" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-5107.html"/>
        <description>The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field.  NOTE: there may be limited scenarios in which this issue is relevant.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T08:31:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:25.909-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:40.123-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:47.505-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:26218 - Corrected two references on RHSA advisory with mistype in ref_id" date="2015-02-16T13:01:00.980-05:00">
              <contributor organization="Positive Technologies">Alexander Leonov</contributor>
            </modified>
            <status_change date="2015-02-16T13:05:05.184-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:20.976-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssh-askpass is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:121375"/>
          <criterion comment="openssh-server is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:121451"/>
          <criterion comment="pam_ssh_agent_auth is earlier than 0:0.9.3-94.el6" test_ref="oval:org.mitre.oval:tst:120715"/>
          <criterion comment="openssh-clients is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:121417"/>
          <criterion comment="openssh-ldap is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:121047"/>
          <criterion comment="openssh is earlier than 0:5.3p1-94.el6" test_ref="oval:org.mitre.oval:tst:120970"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26184" version="3" class="patch">
      <metadata>
        <title>RHSA-2013-1701: sudo security, bug fix and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1701-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1701.html"/>
        <reference source="CESA" ref_id="CESA-2013:1701"/>
        <reference source="CVE" ref_id="CVE-2013-1775" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1775.html"/>
        <reference source="CVE" ref_id="CVE-2013-1776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1776.html"/>
        <reference source="CVE" ref_id="CVE-2013-1777" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1777.html"/>
        <description>An updated sudo package that fixes two security issues, several bugs, and adds two enhancements is now available for Red Hat Enterprise Linux 6.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T08:31:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:34.227-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:35.627-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:43.192-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="sudo is earlier than 0:1.8.6p3-12.el6" test_ref="oval:org.mitre.oval:tst:121277"/>
          <criterion comment="sudo-devel is earlier than 0:1.8.6p3-12.el6" test_ref="oval:org.mitre.oval:tst:121413"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26175" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1648: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1648-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1648.html"/>
        <reference source="CVE" ref_id="CVE-2014-0558" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0558.html"/>
        <reference source="CVE" ref_id="CVE-2014-0564" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0564.html"/>
        <reference source="CVE" ref_id="CVE-2014-0569" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0569.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-22,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0558, CVE-2014-0564, CVE-2014-0569)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.411.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-10-17T11:36:58">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-10-17T23:29:25.877-04:00">DRAFT</status_change>
            <status_change date="2014-11-03T04:00:10.152-05:00">INTERIM</status_change>
            <status_change date="2014-11-24T04:00:13.975-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.411-1.el5" test_ref="oval:org.mitre.oval:tst:124405"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.411-1.el6" test_ref="oval:org.mitre.oval:tst:125231"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26083" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1645: Red Hat Enterprise Linux 6 kernel update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1645-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1645.html"/>
        <reference source="CESA" ref_id="CESA-2013:1645"/>
        <reference source="CVE" ref_id="CVE-2012-6542" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6542.html"/>
        <reference source="CVE" ref_id="CVE-2012-6545" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6545.html"/>
        <reference source="CVE" ref_id="CVE-2013-0343" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0343.html"/>
        <reference source="CVE" ref_id="CVE-2013-1928" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1928.html"/>
        <reference source="CVE" ref_id="CVE-2013-1929" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1929.html"/>
        <reference source="CVE" ref_id="CVE-2013-2164" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2164.html"/>
        <reference source="CVE" ref_id="CVE-2013-2234" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2234.html"/>
        <reference source="CVE" ref_id="CVE-2013-2851" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2851.html"/>
        <reference source="CVE" ref_id="CVE-2013-2888" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2888.html"/>
        <reference source="CVE" ref_id="CVE-2013-2889" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2889.html"/>
        <reference source="CVE" ref_id="CVE-2013-2892" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2892.html"/>
        <reference source="CVE" ref_id="CVE-2013-3231" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3231.html"/>
        <reference source="CVE" ref_id="CVE-2013-4345" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4345.html"/>
        <reference source="CVE" ref_id="CVE-2013-4387" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4387.html"/>
        <reference source="CVE" ref_id="CVE-2013-4591" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4591.html"/>
        <reference source="CVE" ref_id="CVE-2013-4592" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4592.html"/>
        <description>Updated kernel packages that fix multiple security issues, address several hundred bugs, and add numerous enhancements are now available as part of the ongoing support and maintenance of Red Hat Enterprise Linux version 6.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T08:31:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:31.621-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:28.287-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:34.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:120938"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:121246"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:121345"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:121455"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:121408"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:121221"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:120863"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:120544"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:120839"/>
          <criterion comment="kernel is earlier than 0:2.6.32-431.el6" test_ref="oval:org.mitre.oval:tst:120724"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26042" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:1041: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:1041-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-1041.html"/>
        <reference source="CVE" ref_id="CVE-2014-4208" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4208.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4220" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4220.html"/>
        <reference source="CVE" ref_id="CVE-2014-4221" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4221.html"/>
        <reference source="CVE" ref_id="CVE-2014-4227" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4227.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4265" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4265.html"/>
        <reference source="CVE" ref_id="CVE-2014-4266" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4266.html"/>
        <description>IBM Java SE version 7 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-4208, CVE-2014-4209,
CVE-2014-4218, CVE-2014-4219, CVE-2014-4220, CVE-2014-4221, CVE-2014-4227,
CVE-2014-4244, CVE-2014-4252, CVE-2014-4262, CVE-2014-4263, CVE-2014-4265,
CVE-2014-4266)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

All users of java-1.7.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 7 SR7-FP1 release. All running
instances of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-18T12:09:18">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-09-05T14:28:56.428-04:00">DRAFT</status_change>
            <status_change date="2014-09-22T04:00:36.889-04:00">INTERIM</status_change>
            <status_change date="2014-10-13T04:00:19.105-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122406"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122155"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122424"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122504"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122622"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:122508"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122134"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122122"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122662"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122550"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122312"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:122672"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26024" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1543: samba4 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1543-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1543.html"/>
        <reference source="CESA" ref_id="CESA-2013:1543"/>
        <reference source="CVE" ref_id="CVE-2013-4124" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4124.html"/>
        <description>Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T08:31:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:35.903-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:22.598-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:29.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121414"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121330"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121415"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:120829"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121315"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121411"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:120730"/>
          <criterion comment="samba4-python is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:120504"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121251"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121360"/>
          <criterion comment="samba4 is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121344"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121432"/>
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121060"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-58.el6.rc4" test_ref="oval:org.mitre.oval:tst:121263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25908" version="3" class="patch">
      <metadata>
        <title>RHSA-2013:1652: coreutils security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>coreutils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1652-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1652.html"/>
        <reference source="CESA" ref_id="CESA-2013:1652"/>
        <reference source="CVE" ref_id="CVE-2013-0221" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0221.html"/>
        <reference source="CVE" ref_id="CVE-2013-0222" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0222.html"/>
        <reference source="CVE" ref_id="CVE-2013-0223" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0223.html"/>
        <description>Updated coreutils packages that fix three security issues, several bugs, and add two enhancements are now available for Red Hat Enterprise Linux 6.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T08:31:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:29.409-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:17.717-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:23.255-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="coreutils is earlier than 0:8.4-31.el6" test_ref="oval:org.mitre.oval:tst:121389"/>
          <criterion comment="coreutils-libs is earlier than 0:8.4-31.el6" test_ref="oval:org.mitre.oval:tst:121339"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25729" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0981: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0981-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0981.html"/>
        <reference source="CESA" ref_id="CESA-2014:0981"/>
        <reference source="CVE" ref_id="CVE-2012-6647" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6647.html"/>
        <reference source="CVE" ref_id="CVE-2013-7339" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-7339.html"/>
        <reference source="CVE" ref_id="CVE-2014-2672" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2672.html"/>
        <reference source="CVE" ref_id="CVE-2014-2678" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2678.html"/>
        <reference source="CVE" ref_id="CVE-2014-2706" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2706.html"/>
        <reference source="CVE" ref_id="CVE-2014-2851" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2851.html"/>
        <reference source="CVE" ref_id="CVE-2014-3144" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3144.html"/>
        <reference source="CVE" ref_id="CVE-2014-3145" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3145.html"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A use-after-free flaw was found in the way the ping_init_sock() function
of the Linux kernel handled the group_info reference counter. A local,
unprivileged user could use this flaw to crash the system or, potentially,
escalate their privileges on the system. (CVE-2014-2851, Important)

* A NULL pointer dereference flaw was found in the way the
futex_wait_requeue_pi() function of the Linux kernel's futex subsystem
handled the requeuing of certain Priority Inheritance (PI) futexes.
A local, unprivileged user could use this flaw to crash the system.
(CVE-2012-6647, Moderate)

* A NULL pointer dereference flaw was found in the rds_ib_laddr_check()
function in the Linux kernel's implementation of Reliable Datagram Sockets
(RDS). A local, unprivileged user could use this flaw to crash the system.
(CVE-2013-7339, Moderate)

* It was found that a remote attacker could use a race condition flaw in
the ath_tx_aggr_sleep() function to crash the system by creating large
network traffic on the system's Atheros 9k wireless network adapter.
(CVE-2014-2672, Moderate)

* A NULL pointer dereference flaw was found in the rds_iw_laddr_check()
function in the Linux kernel's implementation of Reliable Datagram Sockets
(RDS). A local, unprivileged user could use this flaw to crash the system.
(CVE-2014-2678, Moderate)

* A race condition flaw was found in the way the Linux kernel's mac80211
subsystem implementation handled synchronization between TX and STA wake-up
code paths. A remote attacker could use this flaw to crash the system.
(CVE-2014-2706, Moderate)

* An out-of-bounds memory access flaw was found in the Netlink Attribute
extension of the Berkeley Packet Filter (BPF) interpreter functionality in
the Linux kernel's networking implementation. A local, unprivileged user
could use this flaw to crash the system or leak kernel memory to user space
via a specially crafted socket filter. (CVE-2014-3144, CVE-2014-3145,
Moderate)

This update also fixes several bugs and adds one enhancement.
Documentation for these changes will be available shortly from the
Technical Notes document linked to in the References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues and add this
enhancement. The system must be rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T10:24:53">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:27.393-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:12.748-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:19.575-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121291"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121501"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121010"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121456"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121253"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:120933"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:120822"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121431"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121181"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121002"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121300"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121234"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.23.3.el6" test_ref="oval:org.mitre.oval:tst:121145"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25668" version="3" class="patch">
      <metadata>
        <title>RHSA-2013-1542: samba security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1542-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1542.html"/>
        <reference source="CESA" ref_id="CESA-2013:1542"/>
        <reference source="CVE" ref_id="CVE-2013-0213" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0213.html"/>
        <reference source="CVE" ref_id="CVE-2013-0214" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0214.html"/>
        <reference source="CVE" ref_id="CVE-2013-4124" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4124.html"/>
        <description>These updated samba packages include numerous bug fixes and one element.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-08-05T08:31:03">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-08-07T15:02:33.011-04:00">DRAFT</status_change>
            <status_change date="2014-08-25T04:01:10.143-04:00">INTERIM</status_change>
            <status_change date="2014-09-15T04:00:17.595-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-client is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:120648"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:121366"/>
            <criterion comment="samba is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:121097"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:121406"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:121313"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:120977"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:121280"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:121447"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:120833"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:121466"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:121199"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-164.el6" test_ref="oval:org.mitre.oval:tst:121067"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25428" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0908: java-1.6.0-sun security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0908-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0908.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4216.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4227" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4227.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4265" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4265.html"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch page, listed in the References section. (CVE-2014-4219,
CVE-2014-4216, CVE-2014-4262, CVE-2014-4209, CVE-2014-4218,
CVE-2014-4252, CVE-2014-4244, CVE-2014-4263, CVE-2014-4227,
CVE-2014-4265)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

Note: The way in which the Oracle Java SE packages are delivered has
changed. They now reside in a separate channel/repository that requires
action from the user to perform prior to getting updated packages.
For information on subscribing to the new channel/repository please refer
to: https://access.redhat.com/solutions/732883

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 81 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:00:47.528-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:04:17.819-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:02:19.490-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115505"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:116062"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115401"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:116084"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:116089"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.81-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:115789"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116078"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115370"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116305"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115363"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115315"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.81-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115322"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25379" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0920: httpd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0920-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0920.html"/>
        <reference source="CESA" ref_id="CESA-2014:0920"/>
        <reference source="CVE" ref_id="CVE-2014-0118" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0118.html"/>
        <reference source="CVE" ref_id="CVE-2014-0226" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0226.html"/>
        <reference source="CVE" ref_id="CVE-2014-0231" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0231.html"/>
        <description>The httpd packages provide the Apache HTTP Server, a powerful, efficient,
and extensible web server.

A race condition flaw, leading to heap-based buffer overflows, was found in
the mod_status httpd module. A remote attacker able to access a status page
served by mod_status on a server using a threaded Multi-Processing Module
(MPM) could send a specially crafted request that would cause the httpd
child process to crash or, possibly, allow the attacker to execute
arbitrary code with the privileges of the "apache" user. (CVE-2014-0226)

A denial of service flaw was found in the way httpd's mod_deflate module
handled request body decompression (configured via the "DEFLATE" input
filter). A remote attacker able to send a request whose body would be
decompressed could use this flaw to consume an excessive amount of system
memory and CPU on the target system. (CVE-2014-0118)

A denial of service flaw was found in the way httpd's mod_cgid module
executed CGI scripts that did not read data from the standard input.
A remote attacker could submit a specially crafted request that would cause
the httpd child process to hang indefinitely. (CVE-2014-0231)

All httpd users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, the httpd daemon will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:11.071-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:04:06.499-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:02:07.085-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd is earlier than 0:2.2.3-87.el5_10" test_ref="oval:org.mitre.oval:tst:116175"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-87.el5_10" test_ref="oval:org.mitre.oval:tst:116210"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-87.el5_10" test_ref="oval:org.mitre.oval:tst:116201"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-87.el5_10" test_ref="oval:org.mitre.oval:tst:116271"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd is earlier than 0:2.2.3-87.el5.centos" test_ref="oval:org.mitre.oval:tst:115938"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-87.el5.centos" test_ref="oval:org.mitre.oval:tst:115372"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-87.el5.centos" test_ref="oval:org.mitre.oval:tst:116114"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-87.el5.centos" test_ref="oval:org.mitre.oval:tst:116196"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd is earlier than 0:2.2.15-31.el6_5" test_ref="oval:org.mitre.oval:tst:115650"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-31.el6_5" test_ref="oval:org.mitre.oval:tst:116136"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-31.el6_5" test_ref="oval:org.mitre.oval:tst:115382"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-31.el6_5" test_ref="oval:org.mitre.oval:tst:116334"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-31.el6_5" test_ref="oval:org.mitre.oval:tst:116330"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd is earlier than 0:2.2.15-31.el6.centos" test_ref="oval:org.mitre.oval:tst:116217"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-31.el6.centos" test_ref="oval:org.mitre.oval:tst:116354"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-31.el6.centos" test_ref="oval:org.mitre.oval:tst:116323"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-31.el6.centos" test_ref="oval:org.mitre.oval:tst:115768"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-31.el6.centos" test_ref="oval:org.mitre.oval:tst:116289"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25376" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: RHSA-2014:0861: lzo security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>lzo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0861-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0861.html"/>
        <reference source="CESA" ref_id="CESA-2014:0861"/>
        <reference source="CVE" ref_id="CVE-2014-4607" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4607.html"/>
        <description>LZO is a portable lossless data compression library written in ANSI C.

An integer overflow flaw was found in the way the lzo library decompressed
certain archives compressed with the LZO algorithm. An attacker could
create a specially crafted LZO-compressed input that, when decompressed by
an application using the lzo library, would cause that application to crash
or, potentially, execute arbitrary code. (CVE-2014-4607)

Red Hat would like to thank Don A. Bailey from Lab Mouse Security for
reporting this issue.

All lzo users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the lzo library must be restarted or the
system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:00:46.858-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:04:06.226-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:02:06.777-04:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-11T18:25:24.101-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T18:25:24.101-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="lzo is earlier than 0:2.03-3.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:116180"/>
            <criterion comment="lzo-devel is earlier than 0:2.03-3.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:116081"/>
            <criterion comment="lzo-minilzo is earlier than 0:2.03-3.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:116177"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="lzo is earlier than 0:2.06-6.el7_0.2" test_ref="oval:org.mitre.oval:tst:116205"/>
            <criterion comment="lzo-devel is earlier than 0:2.06-6.el7_0.2" test_ref="oval:org.mitre.oval:tst:115695"/>
            <criterion comment="lzo-minilzo is earlier than 0:2.06-6.el7_0.2" test_ref="oval:org.mitre.oval:tst:115769"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25359" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:0924: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference ref_id="RHSA-2014:0924-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0924.html" source="VENDOR"/>
        <reference ref_id="CESA-2014:0924" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-July/020444.html" source="CESA-2014:0924"/>
        <reference ref_id="CVE-2014-4699" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4699.html" source="CVE"/>
        <reference ref_id="CVE-2014-4943" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4943.html" source="CVE"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* It was found that the Linux kernel's ptrace subsystem allowed a traced
process' instruction pointer to be set to a non-canonical memory address
without forcing the non-sysret code path when returning to user space.
A local, unprivileged user could use this flaw to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-4699,
Important)

Note: The CVE-2014-4699 issue only affected systems using an Intel CPU.

* A flaw was found in the way the pppol2tp_setsockopt() and
pppol2tp_getsockopt() functions in the Linux kernel's PPP over L2TP
implementation handled requests with a non-SOL_PPPOL2TP socket option
level. A local, unprivileged user could use this flaw to escalate their
privileges on the system. (CVE-2014-4943, Important)

Red Hat would like to thank Andy Lutomirski for reporting CVE-2014-4699,
and Sasha Levin for reporting CVE-2014-4943.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:19.319-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:04:03.683-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:02:03.744-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25359 - CentOS checks added for RHEL vulnerabilities." date="2014-11-13T08:36:00.372-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-11-13T08:48:02.639-05:00">INTERIM</status_change>
            <status_change date="2014-12-01T04:00:32.905-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:116314"/>
            <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:116371"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:115732"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:115967"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:116372"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:115956"/>
            <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:115677"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:115478"/>
            <criterion comment="perf is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:116214"/>
            <criterion comment="python-perf is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:115972"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="kernel-debug-debuginfo is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:135260"/>
            <criterion comment="kernel-debuginfo is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:135106"/>
            <criterion comment="kernel-debuginfo-common-i686 is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:135338"/>
            <criterion comment="perf-debuginfo is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:134491"/>
            <criterion comment="python-perf-debuginfo is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:135131"/>
            <criterion comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-431.20.5.el6" test_ref="oval:org.mitre.oval:tst:134423"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25358" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0907: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0907-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0907.html"/>
        <reference source="CESA" ref_id="CESA-2014:0907"/>
        <reference source="CVE" ref_id="CVE-2014-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2490.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4216.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4266" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4266.html"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

It was discovered that the Hotspot component in OpenJDK did not properly
verify bytecode from the class files. An untrusted Java application or
applet could possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-4216, CVE-2014-4219)

A format string flaw was discovered in the Hotspot component event logger
in OpenJDK. An untrusted Java application or applet could use this flaw to
crash the Java Virtual Machine or, potentially, execute arbitrary code with
the privileges of the Java Virtual Machine. (CVE-2014-2490)

An improper permission check issue was discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
this flaw to bypass Java sandbox restrictions. (CVE-2014-4262)

Multiple flaws were discovered in the JMX, Libraries, Security, and
Serviceability components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2014-4209, CVE-2014-4218, CVE-2014-4252, CVE-2014-4266)

It was discovered that the RSA algorithm in the Security component in
OpenJDK did not sufficiently perform blinding while performing operations
that were using private keys. An attacker able to measure timing
differences of those operations could possibly leak information about the
used keys. (CVE-2014-4244)

The Diffie-Hellman (DH) key exchange algorithm implementation in the
Security component in OpenJDK failed to validate public DH parameters
properly. This could cause OpenJDK to accept and use weak parameters,
allowing an attacker to recover the negotiated key. (CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

This update also fixes the following bug:

* Prior to this update, an application accessing an unsynchronized HashMap
could potentially enter an infinite loop and consume an excessive amount of
CPU resources. This update resolves this issue. (BZ#1115580)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:00:55.436-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:04:02.852-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:02:03.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el5_10" test_ref="oval:org.mitre.oval:tst:116193"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el5_10" test_ref="oval:org.mitre.oval:tst:115888"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el5_10" test_ref="oval:org.mitre.oval:tst:116093"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el5_10" test_ref="oval:org.mitre.oval:tst:116146"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el5_10" test_ref="oval:org.mitre.oval:tst:116148"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:116179"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:116211"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:116107"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:116029"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el6_5" test_ref="oval:org.mitre.oval:tst:116192"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:116140"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:116166"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:115881"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:115700"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el7_0" test_ref="oval:org.mitre.oval:tst:115804"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25312" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0902: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0902-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0902.html"/>
        <reference source="CVE" ref_id="CVE-2014-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2483.html"/>
        <reference source="CVE" ref_id="CVE-2014-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2490.html"/>
        <reference source="CVE" ref_id="CVE-2014-4208" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4208.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4216.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4220" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4220.html"/>
        <reference source="CVE" ref_id="CVE-2014-4221" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4221.html"/>
        <reference source="CVE" ref_id="CVE-2014-4223" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4223.html"/>
        <reference source="CVE" ref_id="CVE-2014-4227" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4227.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4264" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4264.html"/>
        <reference source="CVE" ref_id="CVE-2014-4265" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4265.html"/>
        <reference source="CVE" ref_id="CVE-2014-4266" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4266.html"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2014-4219, CVE-2014-2490, CVE-2014-4216, CVE-2014-4223, CVE-2014-4262,
CVE-2014-2483, CVE-2014-4209, CVE-2014-4218, CVE-2014-4252, CVE-2014-4266,
CVE-2014-4221, CVE-2014-4244, CVE-2014-4263, CVE-2014-4227, CVE-2014-4265,
CVE-2014-4220, CVE-2014-4208, CVE-2014-4264)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

Note: The way in which the Oracle Java SE packages are delivered has
changed. They now reside in a separate channel/repository that requires
action from the user to perform prior to getting updated packages.
For information on subscribing to the new channel/repository please refer
to: https://access.redhat.com/solutions/732883

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 65 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:24.874-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:51.600-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:01:47.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:116159"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:115925"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:115810"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:115721"/>
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:115380"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.65-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:115708"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116208"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115996"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:115979"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116130"/>
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116045"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.65-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:116028"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25271" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0866: samba and samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0866-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0866.html"/>
        <reference source="CESA" ref_id="CESA-2014:0866"/>
        <reference source="CVE" ref_id="CVE-2014-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0244.html"/>
        <reference source="CVE" ref_id="CVE-2014-3493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3493.html"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A denial of service flaw was found in the way the sys_recvfile() function
of nmbd, the NetBIOS message block daemon, processed non-blocking sockets.
An attacker could send a specially crafted packet that, when processed,
would cause nmbd to enter an infinite loop and consume an excessive amount
of CPU time. (CVE-2014-0244)

It was discovered that smbd, the Samba file server daemon, did not properly
handle certain files that were stored on the disk and used a valid Unicode
character in the file name. An attacker able to send an authenticated
non-Unicode request that attempted to read such a file could cause smbd to
crash. (CVE-2014-3493)

Red Hat would like to thank Daniel Berteaud of FIREWALL-SERVICES SARL for
reporting CVE-2014-0244, and the Samba project for reporting CVE-2014-3493.
The Samba project acknowledges Simon Arlott as the original reporter of
CVE-2014-3493.

All Samba users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-21T11:31:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-25T11:59:58.068-04:00">DRAFT</status_change>
            <status_change date="2014-08-11T04:01:03.078-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:07.457-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115866"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115752"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115828"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115827"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115213"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115671"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115545"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115293"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115904"/>
            <criterion comment="samba is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115588"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115108"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115089"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115719"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115699"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115908"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115002"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115794"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115854"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115998"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25270" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0919: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0919-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0919.html"/>
        <reference source="CESA" ref_id="CESA-2014:0919"/>
        <reference source="CVE" ref_id="CVE-2014-1547" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1547.html"/>
        <reference source="CVE" ref_id="CVE-2014-1555" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1555.html"/>
        <reference source="CVE" ref_id="CVE-2014-1556" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1556.html"/>
        <reference source="CVE" ref_id="CVE-2014-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1557.html"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1547, CVE-2014-1555, CVE-2014-1556, CVE-2014-1557)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, David Keeler, Byron Campen, Jethro
Beekman, Patrick Cozzi, and Mozilla community member John as the original
reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.7.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.7.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:00:58.850-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:41.731-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:01:31.561-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.7.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:116099"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.7.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:116303"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="firefox is earlier than 0:24.7.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:116256"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.7.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:116333"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 7 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.7.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:116085"/>
            <criterion comment="xulrunner is earlier than 0:24.7.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115740"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.7.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115371"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 7 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.7.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:116167"/>
            <criterion comment="xulrunner is earlier than 0:24.7.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:115784"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.7.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:115931"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25229" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0861: lzo security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>lzo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0861-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0861.html"/>
        <reference source="CESA" ref_id="CESA-2014:0861"/>
        <reference source="CVE" ref_id="CVE-2014-4607" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4607.html"/>
        <description>LZO is a portable lossless data compression library written in ANSI C.

An integer overflow flaw was found in the way the lzo library decompressed
certain archives compressed with the LZO algorithm. An attacker could
create a specially crafted LZO-compressed input that, when decompressed by
an application using the lzo library, would cause that application to crash
or, potentially, execute arbitrary code. (CVE-2014-4607)

Red Hat would like to thank Don A. Bailey from Lab Mouse Security for
reporting this issue.

All lzo users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the lzo library must be restarted or the
system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-21T11:31:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-25T11:59:54.965-04:00">DRAFT</status_change>
            <status_change date="2014-08-11T04:01:00.594-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:03:05.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="lzo is earlier than 0:2.03-3.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:115897"/>
            <criterion comment="lzo-devel is earlier than 0:2.03-3.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:115746"/>
            <criterion comment="lzo-minilzo is earlier than 0:2.03-3.1.el6_5.1" test_ref="oval:org.mitre.oval:tst:115694"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="lzo is earlier than 0:2.06-6.el7_0.2" test_ref="oval:org.mitre.oval:tst:115927"/>
            <criterion comment="lzo-devel is earlier than 0:2.06-6.el7_0.2" test_ref="oval:org.mitre.oval:tst:115839"/>
            <criterion comment="lzo-minilzo is earlier than 0:2.06-6.el7_0.2" test_ref="oval:org.mitre.oval:tst:115880"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25210" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0860: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0860-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0860.html"/>
        <reference source="CVE" ref_id="CVE-2014-0537" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0537.html"/>
        <reference source="CVE" ref_id="CVE-2014-0539" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0539.html"/>
        <reference source="CVE" ref_id="CVE-2014-4671" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4671.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-17,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0537, CVE-2014-0539)

This update also fixes a flaw that would lead to Cross-Site Request Forgery
(CSRF) attacks. (CVE-2014-4671)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.394.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:12.002-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:29.634-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:01:15.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.394-1.el5" test_ref="oval:org.mitre.oval:tst:116002"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.394-1.el6" test_ref="oval:org.mitre.oval:tst:116066"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25155" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0426: qemu-kvm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0426-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0426.html"/>
        <reference source="CVE" ref_id="CVE-2014-0142" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0142.html"/>
        <reference source="CVE" ref_id="CVE-2014-0143" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0143.html"/>
        <reference source="CVE" ref_id="CVE-2014-0144" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0144.html"/>
        <reference source="CVE" ref_id="CVE-2014-0145" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0145.html"/>
        <reference source="CVE" ref_id="CVE-2014-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0146.html"/>
        <reference source="CVE" ref_id="CVE-2014-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0147.html"/>
        <reference source="CVE" ref_id="CVE-2014-0148" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0148.html"/>
        <reference source="CVE" ref_id="CVE-2014-0150" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0150.html"/>
        <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. qemu-kvm is the user-space component
for running virtual machines using KVM.

...

All users of qemu-kvm should upgrade to these updated packages, which
contain backported patches to correct this issue. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:07.964-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:22.472-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:01:06.276-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:115697"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:115384"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:115503"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:115756"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25138" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0788: mod_wsgi security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mod_wsgi</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0788-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0788.html"/>
        <reference source="CESA" ref_id="CESA-2014:0788"/>
        <reference source="CVE" ref_id="CVE-2014-0240" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0240.html"/>
        <reference source="CVE" ref_id="CVE-2014-0242" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0242.html"/>
        <description>The mod_wsgi adapter is an Apache module that provides a WSGI-compliant
interface for hosting Python-based web applications within Apache.

It was found that mod_wsgi did not properly drop privileges if the call to
setuid() failed. If mod_wsgi was set up to allow unprivileged users to run
WSGI applications, a local user able to run a WSGI application could
possibly use this flaw to escalate their privileges on the system.
(CVE-2014-0240)

Note: mod_wsgi is not intended to provide privilege separation for WSGI
applications. Systems relying on mod_wsgi to limit or sandbox the
privileges of mod_wsgi applications should migrate to a different solution
with proper privilege separation.

It was discovered that mod_wsgi could leak memory of a hosted web
application via the "Content-Type" header. A remote attacker could possibly
use this flaw to disclose limited portions of the web application's memory.
(CVE-2014-0242)

Red Hat would like to thank Graham Dumpleton for reporting these issues.
Upstream acknowledges RÃ³bert Kisteleki as the original reporter of
CVE-2014-0240, and Buck Golemon as the original reporter of CVE-2014-0242.

All mod_wsgi users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T17:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:28.782-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:50.675-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:03:20.837-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="mod_wsgi is earlier than 0:3.2-6.el6_5" test_ref="oval:org.mitre.oval:tst:114605"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25127" version="4" class="patch">
      <metadata>
        <title>RHSA-2014:0790: dovecot security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>dovecot</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0790-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0790.html"/>
        <reference source="CESA" ref_id="CESA-2014:0790"/>
        <reference source="CVE" ref_id="CVE-2014-3430" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3430.html"/>
        <description>Dovecot is an IMAP server, written with security primarily in mind, for
Linux and other UNIX-like systems. It also contains a small POP3 server.
It supports mail in both the maildir or mbox format. The SQL drivers and
authentication plug-ins are provided as subpackages.

It was discovered that Dovecot did not properly discard connections trapped
in the SSL/TLS handshake phase. A remote attacker could use this flaw to
cause a denial of service on an IMAP/POP3 server by exhausting the pool of
available connections and preventing further, legitimate connections to the
IMAP/POP3 server to be made. (CVE-2014-3430)

All dovecot users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
updated packages, the dovecot service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T17:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:33.028-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:50.527-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:25127 - 3 patches on RHEL where CentOS checks were added" date="2014-07-28T18:10:00.421-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-18T04:03:19.698-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dovecot-pigeonhole is earlier than 1:2.0.9-7.el6_5.1" test_ref="oval:org.mitre.oval:tst:115565"/>
            <criterion comment="dovecot-mysql is earlier than 1:2.0.9-7.el6_5.1" test_ref="oval:org.mitre.oval:tst:114827"/>
            <criterion comment="dovecot is earlier than 1:2.0.9-7.el6_5.1" test_ref="oval:org.mitre.oval:tst:115465"/>
            <criterion comment="dovecot-devel is earlier than 1:2.0.9-7.el6_5.1" test_ref="oval:org.mitre.oval:tst:115468"/>
            <criterion comment="dovecot-pgsql is earlier than 1:2.0.9-7.el6_5.1" test_ref="oval:org.mitre.oval:tst:115126"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dovecot-pigeonhole is earlier than 1:2.2.10-4.el7_0.1" test_ref="oval:org.mitre.oval:tst:115404"/>
            <criterion comment="dovecot-mysql is earlier than 1:2.2.10-4.el7_0.1" test_ref="oval:org.mitre.oval:tst:115453"/>
            <criterion comment="dovecot is earlier than 1:2.2.10-4.el7_0.1" test_ref="oval:org.mitre.oval:tst:115504"/>
            <criterion comment="dovecot-pgsql is earlier than 1:2.2.10-4.el7_0.1" test_ref="oval:org.mitre.oval:tst:115161"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25125" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0743: qemu-kvm security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0743-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0743.html"/>
        <reference source="CESA" ref_id="CESA-2014:0743"/>
        <reference source="CVE" ref_id="CVE-2013-4148" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4148.html"/>
        <reference source="CVE" ref_id="CVE-2013-4151" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4151.html"/>
        <reference source="CVE" ref_id="CVE-2013-4535" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4535.html"/>
        <reference source="CVE" ref_id="CVE-2013-4536" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4536.html"/>
        <reference source="CVE" ref_id="CVE-2013-4541" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4541.html"/>
        <reference source="CVE" ref_id="CVE-2013-4542" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4542.html"/>
        <reference source="CVE" ref_id="CVE-2013-6399" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6399.html"/>
        <reference source="CVE" ref_id="CVE-2014-0182" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0182.html"/>
        <reference source="CVE" ref_id="CVE-2014-2894" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2894.html"/>
        <reference source="CVE" ref_id="CVE-2014-3461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3461.html"/>
        <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

Multiple buffer overflow, input validation, and out-of-bounds write flaws
were found in the way the virtio, virtio-net, virtio-scsi, and usb drivers
of QEMU handled state loading after migration. A user able to alter the
savevm data (either on the disk or over the wire during migration) could
use either of these flaws to corrupt QEMU process memory on the
(destination) host, which could potentially result in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2013-4148, CVE-2013-4151, CVE-2013-4535, CVE-2013-4536, CVE-2013-4541,
CVE-2013-4542, CVE-2013-6399, CVE-2014-0182, CVE-2014-3461)

An out-of-bounds memory access flaw was found in the way QEMU's IDE device
driver handled the execution of SMART EXECUTE OFFLINE commands.
A privileged guest user could use this flaw to corrupt QEMU process memory
on the host, which could potentially result in arbitrary code execution on
the host with the privileges of the QEMU process. (CVE-2014-2894)

The CVE-2013-4148, CVE-2013-4151, CVE-2013-4535, CVE-2013-4536,
CVE-2013-4541, CVE-2013-4542, CVE-2013-6399, CVE-2014-0182, and
CVE-2014-3461 issues were discovered by Michael S. Tsirkin of Red Hat,
Anthony Liguori, and Michael Roth.

This update also fixes the following bugs:

* Previously, under certain circumstances, libvirt failed to start guests
which used a non-zero PCI domain and SR-IOV Virtual Functions (VFs), and
returned the following error message:

Can't assign device inside non-zero PCI segment as this KVM module doesn't
support it.

This update fixes this issue and guests using the aforementioned
configuration no longer fail to start. (BZ#1099941)

* Due to an incorrect initialization of the cpus_sts bitmap, which holds
the enablement status of a vCPU, libvirt could fail to start a guest with
an unusual vCPU topology (for example, a guest with three cores and two
sockets). With this update, the initialization of cpus_sts has been
corrected, and libvirt no longer fails to start the aforementioned guests.
(BZ#1100575)

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T17:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:31.198-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:49.966-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:03:19.103-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.10" test_ref="oval:org.mitre.oval:tst:115431"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.10" test_ref="oval:org.mitre.oval:tst:115065"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.10" test_ref="oval:org.mitre.oval:tst:115375"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.10" test_ref="oval:org.mitre.oval:tst:115261"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25116" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0917: nss and nspr security, bug fix, and enhancement update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0917-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0917.html"/>
        <reference source="CESA" ref_id="CESA-2014:0917"/>
        <reference source="CVE" ref_id="CVE-2013-1740" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1740.html"/>
        <reference source="CVE" ref_id="CVE-2014-1490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1490.html"/>
        <reference source="CVE" ref_id="CVE-2014-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1491.html"/>
        <reference source="CVE" ref_id="CVE-2014-1492" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1492.html"/>
        <reference source="CVE" ref_id="CVE-2014-1544" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1544.html"/>
        <reference source="CVE" ref_id="CVE-2014-1545" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1545.html"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

A race condition was found in the way NSS verified certain certificates.
A remote attacker could use this flaw to crash an application using NSS or,
possibly, execute arbitrary code with the privileges of the user running
that application. (CVE-2014-1544)

A flaw was found in the way TLS False Start was implemented in NSS.
An attacker could use this flaw to potentially return unencrypted
information from the server. (CVE-2013-1740)

A race condition was found in the way NSS implemented session ticket
handling as specified by RFC 5077. An attacker could use this flaw to crash
an application using NSS or, in rare cases, execute arbitrary code with the
privileges of the user running that application. (CVE-2014-1490)

It was found that NSS accepted weak Diffie-Hellman Key exchange (DHKE)
parameters. This could possibly lead to weak encryption being used in
communication between the client and the server. (CVE-2014-1491)

An out-of-bounds write flaw was found in NSPR. A remote attacker could
potentially use this flaw to crash an application using NSPR or, possibly,
execute arbitrary code with the privileges of the user running that
application. This NSPR flaw was not exposed to web content in any shipped
version of Firefox. (CVE-2014-1545)

It was found that the implementation of Internationalizing Domain Names in
Applications (IDNA) hostname matching in NSS did not follow the RFC 6125
recommendations. This could lead to certain invalid certificates with
international characters to be accepted as valid. (CVE-2014-1492)

Red Hat would like to thank the Mozilla project for reporting the
CVE-2014-1544, CVE-2014-1490, CVE-2014-1491, and CVE-2014-1545 issues.
Upstream acknowledges Tyson Smith and Jesse Schwartzentruber as the
original reporters of CVE-2014-1544, Brian Smith as the original reporter
of CVE-2014-1490, Antoine Delignat-Lavaud and Karthikeyan Bhargavan as the
original reporters of CVE-2014-1491, and Abhishek Arya as the original
reporter of CVE-2014-1545.

In addition, the nss package has been upgraded to upstream version 3.16.1,
and the nspr package has been upgraded to upstream version 4.10.6. These
updated packages provide a number of bug fixes and enhancements over the
previous versions. (BZ#1112136, BZ#1112135)

Users of NSS and NSPR are advised to upgrade to these updated packages,
which correct these issues and add these enhancements. After installing
this update, applications using NSS or NSPR must be restarted for this
update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:00:57.733-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:18.437-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:01:02.129-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nspr is earlier than 0:4.10.6-1.el6_5" test_ref="oval:org.mitre.oval:tst:116284"/>
          <criterion comment="nspr-devel is earlier than 0:4.10.6-1.el6_5" test_ref="oval:org.mitre.oval:tst:115335"/>
          <criterion comment="nss-util is earlier than 0:3.16.1-1.el6_5" test_ref="oval:org.mitre.oval:tst:116059"/>
          <criterion comment="nss-util-devel is earlier than 0:3.16.1-1.el6_5" test_ref="oval:org.mitre.oval:tst:115945"/>
          <criterion comment="nss is earlier than 0:3.16.1-4.el6_5" test_ref="oval:org.mitre.oval:tst:116150"/>
          <criterion comment="nss-devel is earlier than 0:3.16.1-4.el6_5" test_ref="oval:org.mitre.oval:tst:116255"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.16.1-4.el6_5" test_ref="oval:org.mitre.oval:tst:115997"/>
          <criterion comment="nss-sysinit is earlier than 0:3.16.1-4.el6_5" test_ref="oval:org.mitre.oval:tst:116195"/>
          <criterion comment="nss-tools is earlier than 0:3.16.1-4.el6_5" test_ref="oval:org.mitre.oval:tst:116308"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25062" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: RHSA-2014:0866: samba and samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0866-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0866.html"/>
        <reference source="CESA" ref_id="CESA-2014:0866"/>
        <reference source="CVE" ref_id="CVE-2014-0244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0244.html"/>
        <reference source="CVE" ref_id="CVE-2014-3493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3493.html"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

A denial of service flaw was found in the way the sys_recvfile() function
of nmbd, the NetBIOS message block daemon, processed non-blocking sockets.
An attacker could send a specially crafted packet that, when processed,
would cause nmbd to enter an infinite loop and consume an excessive amount
of CPU time. (CVE-2014-0244)

It was discovered that smbd, the Samba file server daemon, did not properly
handle certain files that were stored on the disk and used a valid Unicode
character in the file name. An attacker able to send an authenticated
non-Unicode request that attempted to read such a file could cause smbd to
crash. (CVE-2014-3493)

Red Hat would like to thank Daniel Berteaud of FIREWALL-SERVICES SARL for
reporting CVE-2014-0244, and the Samba project for reporting CVE-2014-3493.
The Samba project acknowledges Simon Arlott as the original reporter of
CVE-2014-3493.

All Samba users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:02.654-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:09.301-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:00:51.397-04:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-11T18:27:00.643-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T18:27:00.643-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:116253"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115374"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115965"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:116259"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115686"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:116076"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:116190"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.140.el5_10" test_ref="oval:org.mitre.oval:tst:115479"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116200"/>
            <criterion comment="samba is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116223"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115954"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116106"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115675"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116097"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115887"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115270"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116003"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115986"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:115949"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5" test_ref="oval:org.mitre.oval:tst:116128"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25013" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: RHSA-2014:0865: tomcat6 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0865-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0865.html"/>
        <reference source="CESA" ref_id="CESA-2014:0865"/>
        <reference source="CVE" ref_id="CVE-2014-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0075.html"/>
        <reference source="CVE" ref_id="CVE-2014-0096" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0096.html"/>
        <reference source="CVE" ref_id="CVE-2014-0099" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0099.html"/>
        <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was discovered that Apache Tomcat did not limit the length of chunk
sizes when using chunked transfer encoding. A remote attacker could use
this flaw to perform a denial of service attack against Tomcat by streaming
an unlimited quantity of data, leading to excessive consumption of server
resources. (CVE-2014-0075)

It was found that Apache Tomcat did not check for overflowing values when
parsing request content length headers. A remote attacker could use this
flaw to perform an HTTP request smuggling attack on a Tomcat server located
behind a reverse proxy that processed the content length header correctly.
(CVE-2014-0099)

It was found that the org.apache.catalina.servlets.DefaultServlet
implementation in Apache Tomcat allowed the definition of XML External
Entities (XXEs) in provided XSLTs. A malicious application could use this
to circumvent intended security restrictions to disclose sensitive
information. (CVE-2014-0096)

The CVE-2014-0075 issue was discovered by David Jorm of Red Hat Product
Security.

This update also fixes the following bugs:

* The patch that resolved the CVE-2014-0050 issue contained redundant code.
This update removes the redundant code. (BZ#1094528)

* The patch that resolved the CVE-2013-4322 issue contained an invalid
check that triggered a java.io.EOFException while reading trailer headers
for chunked requests. This update fixes the check and the aforementioned
exception is no longer triggered in the described scenario. (BZ#1095602)

All Tomcat 6 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:23.820-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:03:05.022-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:00:46.364-04:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-11T18:27:58.242-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T18:27:58.242-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:116250"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:116072"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115496"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115706"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115868"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:116119"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:116171"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:116001"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24924" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0771: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0771-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0771.html"/>
        <reference source="CESA" ref_id="CESA-2014:0771"/>
        <reference source="CVE" ref_id="CVE-2013-6378" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6378.html"/>
        <reference source="CVE" ref_id="CVE-2014-0203" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0203.html"/>
        <reference source="CVE" ref_id="CVE-2014-1737" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1737.html"/>
        <reference source="CVE" ref_id="CVE-2014-1738" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1738.html"/>
        <reference source="CVE" ref_id="CVE-2014-1874" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1874.html"/>
        <reference source="CVE" ref_id="CVE-2014-2039" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2039.html"/>
        <reference source="CVE" ref_id="CVE-2014-3153" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3153.html"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's futex subsystem handled
the requeuing of certain Priority Inheritance (PI) futexes. A local,
unprivileged user could use this flaw to escalate their privileges on the
system. (CVE-2014-3153, Important)

* A flaw was found in the way the Linux kernel's floppy driver handled user
space provided data in certain error code paths while processing FDRAWCMD
IOCTL commands. A local user with write access to /dev/fdX could use this
flaw to free (using the kfree() function) arbitrary kernel memory.
(CVE-2014-1737, Important)

* It was found that the Linux kernel's floppy driver leaked internal kernel
memory addresses to user space during the processing of the FDRAWCMD IOCTL
command. A local user with write access to /dev/fdX could use this flaw to
obtain information about the kernel heap arrangement. (CVE-2014-1738, Low)

Note: A local user with write access to /dev/fdX could use these two flaws
(CVE-2014-1737 in combination with CVE-2014-1738) to escalate their
privileges on the system.

* It was discovered that the proc_ns_follow_link() function did not
properly return the LAST_BIND value in the last pathname component as is
expected for procfs symbolic links, which could lead to excessive freeing
of memory and consequent slab corruption. A local, unprivileged user could
use this flaw to crash the system. (CVE-2014-0203, Moderate)

* A flaw was found in the way the Linux kernel handled exceptions when
user-space applications attempted to use the linkage stack. On IBM S/390
systems, a local, unprivileged user could use this flaw to crash the
system. (CVE-2014-2039, Moderate)

* An invalid pointer dereference flaw was found in the Marvell 8xxx
Libertas WLAN (libertas) driver in the Linux kernel. A local user able to
write to a file that is provided by the libertas driver and located on the
debug file system (debugfs) could use this flaw to crash the system. Note:
The debugfs file system must be mounted locally to exploit this issue.
It is not mounted by default. (CVE-2013-6378, Low)

* A denial of service flaw was discovered in the way the Linux kernel's
SELinux implementation handled files with an empty SELinux security
context. A local user who has the CAP_MAC_ADMIN capability could use this
flaw to crash the system. (CVE-2014-1874, Low)

Red Hat would like to thank Kees Cook of Google for reporting
CVE-2014-3153, Matthew Daley for reporting CVE-2014-1737 and CVE-2014-1738,
and Vladimir Davydov of Parallels for reporting CVE-2014-0203. Google
acknowledges Pinkie Pie as the original reporter of CVE-2014-3153.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T17:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:30.204-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:38.627-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:55.650-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115180"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115387"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115563"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115542"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115337"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115603"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115177"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115074"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115137"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115491"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115456"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115580"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.20.3.el6" test_ref="oval:org.mitre.oval:tst:115575"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24892" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0625: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0625-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0625.html"/>
        <reference source="CESA" ref_id="CESA-2014:0625"/>
        <reference source="CVE" ref_id="CVE-2010-5298" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-5298.html"/>
        <reference source="CVE" ref_id="CVE-2014-0195" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0195.html"/>
        <reference source="CVE" ref_id="CVE-2014-0198" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0198.html"/>
        <reference source="CVE" ref_id="CVE-2014-0221" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0221.html"/>
        <reference source="CVE" ref_id="CVE-2014-0224" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0224.html"/>
        <reference source="CVE" ref_id="CVE-2014-3470" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3470.html"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)

Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433

A buffer overflow flaw was found in the way OpenSSL handled invalid DTLS
packet fragments. A remote attacker could possibly use this flaw to execute
arbitrary code on a DTLS client or server. (CVE-2014-0195)

Multiple flaws were found in the way OpenSSL handled read and write buffers
when the SSL_MODE_RELEASE_BUFFERS mode was enabled. A TLS/SSL client or
server using OpenSSL could crash or unexpectedly drop connections when
processing certain SSL traffic. (CVE-2010-5298, CVE-2014-0198)

A denial of service flaw was found in the way OpenSSL handled certain DTLS
ServerHello requests. A specially crafted DTLS handshake packet could cause
a DTLS client using OpenSSL to crash. (CVE-2014-0221)

A NULL pointer dereference flaw was found in the way OpenSSL performed
anonymous Elliptic Curve Diffie Hellman (ECDH) key exchange. A specially
crafted handshake packet could cause a TLS/SSL client that has the
anonymous ECDH cipher suite enabled to crash. (CVE-2014-3470)

Red Hat would like to thank the OpenSSL project for reporting these issues.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of CVE-2014-0224, JÃ¼ri Aedla as the original reporter of CVE-2014-0195,
Imre Rad of Search-Lab as the original reporter of CVE-2014-0221, and Felix
GrÃ¶bert and Ivan FratriÄ‡ of Google as the original reporters of
CVE-2014-3470.

All OpenSSL users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:21.182-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:10:59.368-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:46.893-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:113928"/>
          <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:114826"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:114643"/>
          <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.14" test_ref="oval:org.mitre.oval:tst:114755"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24887" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0560: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0560-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0560.html"/>
        <reference source="CESA" ref_id="CESA-2014:0560"/>
        <reference source="CVE" ref_id="CVE-2014-0179" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0179.html"/>
        <description>The libvirt library is a C API for managing and interacting with the
virtualization capabilities of Linux and other operating systems. In 
addition, libvirt provides tools for remote management of virtualized
systems. 

It was found that libvirt passes the XML_PARSE_NOENT flag when parsing XML
documents using the libxml2 library, in which case all XML entities in the
parsed documents are expanded. A user able to force libvirtd to parse an
XML document with an entity pointing to a special file that blocks on read
access could use this flaw to cause libvirtd to hang indefinitely,
resulting in a denial of service on the system. (CVE-2014-0179)

Red Hat would like to thank the upstream Libvirt project for reporting this
issue. Upstream acknowledges Daniel P. Berrange and Richard Jones as the
original reporters.

This update also fixes the following bugs:

* When hot unplugging a virtual CPU (vCPU), libvirt kept a pointer to
already freed memory if the vCPU was pinned to a host CPU. Consequently,
when reading the CPU pinning information, libvirt terminated unexpectedly
due to an attempt to access this memory. This update ensures that libvirt
releases the pointer to the previously allocated memory when a vCPU is
being hot unplugged, and it no longer crashes in this situation.
(BZ#1091206)

* Previously, libvirt passed an incorrect argument to the "tc" command when
setting quality of service (QoS) on a network interface controller (NIC).
As a consequence, QoS was applied only to IP traffic. With this update,
libvirt constructs the "tc" command correctly so that QoS is applied to all
traffic as expected. (BZ#1096806)

* When using the sanlock daemon for managing access to shared storage,
libvirt expected all QEMU domains to be registered with sanlock. However,
if a QEMU domain was started prior to enabling sanlock, the domain was not
registered with sanlock. Consequently, migration of a virtual machine (VM)
from such a QEMU domain failed with a libvirt error. With this update,
libvirt verifies whether a QEMU domain process is registered with sanlock
before it starts working with the domain, ensuring that migration of
virtual machines works as expected. (BZ#1097227)

All libvirt users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
updated packages, libvirtd will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:17.417-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:10:59.043-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:46.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.8" test_ref="oval:org.mitre.oval:tst:114344"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.8" test_ref="oval:org.mitre.oval:tst:114742"/>
          <criterion comment="libvirt is earlier than 0:0.10.2-29.el6_5.8" test_ref="oval:org.mitre.oval:tst:114687"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.8" test_ref="oval:org.mitre.oval:tst:114793"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.8" test_ref="oval:org.mitre.oval:tst:114873"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24883" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0865: tomcat6 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0865-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0865.html"/>
        <reference source="CESA" ref_id="CESA-2014:0865"/>
        <reference source="CVE" ref_id="CVE-2014-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0075.html"/>
        <reference source="CVE" ref_id="CVE-2014-0096" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0096.html"/>
        <reference source="CVE" ref_id="CVE-2014-0099" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0099.html"/>
        <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was discovered that Apache Tomcat did not limit the length of chunk
sizes when using chunked transfer encoding. A remote attacker could use
this flaw to perform a denial of service attack against Tomcat by streaming
an unlimited quantity of data, leading to excessive consumption of server
resources. (CVE-2014-0075)

It was found that Apache Tomcat did not check for overflowing values when
parsing request content length headers. A remote attacker could use this
flaw to perform an HTTP request smuggling attack on a Tomcat server located
behind a reverse proxy that processed the content length header correctly.
(CVE-2014-0099)

It was found that the org.apache.catalina.servlets.DefaultServlet
implementation in Apache Tomcat allowed the definition of XML External
Entities (XXEs) in provided XSLTs. A malicious application could use this
to circumvent intended security restrictions to disclose sensitive
information. (CVE-2014-0096)

The CVE-2014-0075 issue was discovered by David Jorm of Red Hat Product
Security.

This update also fixes the following bugs:

* The patch that resolved the CVE-2014-0050 issue contained redundant code.
This update removes the redundant code. (BZ#1094528)

* The patch that resolved the CVE-2013-4322 issue contained an invalid
check that triggered a java.io.EOFException while reading trailer headers
for chunked requests. This update fixes the check and the aforementioned
exception is no longer triggered in the described scenario. (BZ#1095602)

All Tomcat 6 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-21T11:31:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-25T11:59:59.875-04:00">DRAFT</status_change>
            <status_change date="2014-08-11T04:00:34.270-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:51.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115943"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115266"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:114945"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115879"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115920"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115099"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115736"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115110"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-72.el6_5" test_ref="oval:org.mitre.oval:tst:115510"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24845" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0448: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0448-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0448.html"/>
        <reference source="CESA" ref_id="CESA-2014:0448"/>
        <reference source="CVE" ref_id="CVE-2014-1518" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1518.html"/>
        <reference source="CVE" ref_id="CVE-2014-1523" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1523.html"/>
        <reference source="CVE" ref_id="CVE-2014-1524" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1524.html"/>
        <reference source="CVE" ref_id="CVE-2014-1529" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1529.html"/>
        <reference source="CVE" ref_id="CVE-2014-1530" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1530.html"/>
        <reference source="CVE" ref_id="CVE-2014-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1531.html"/>
        <reference source="CVE" ref_id="CVE-2014-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1532.html"/>
        <description>Mozilla Firefox is an open source web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)

A use-after-free flaw was found in the way Firefox resolved hosts in
certain circumstances. An attacker could use this flaw to crash Firefox or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1532)

An out-of-bounds read flaw was found in the way Firefox decoded JPEG
images. Loading a web page containing a specially crafted JPEG image could
cause Firefox to crash. (CVE-2014-1523)

A flaw was found in the way Firefox handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith, and Jesse
Schwartzentrube as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.5.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to this updated package, which contains
Firefox version 24.5.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:14.634-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:42.250-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:56.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:113595"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.5.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:113371"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="firefox is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114141"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.5.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:114160"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24842" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0745: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0745-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0745.html"/>
        <reference source="CVE" ref_id="CVE-2014-0531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0531.html"/>
        <reference source="CVE" ref_id="CVE-2014-0532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0532.html"/>
        <reference source="CVE" ref_id="CVE-2014-0533" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0533.html"/>
        <reference source="CVE" ref_id="CVE-2014-0534" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0534.html"/>
        <reference source="CVE" ref_id="CVE-2014-0535" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0535.html"/>
        <reference source="CVE" ref_id="CVE-2014-0536" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0536.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-16,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0534, CVE-2014-0535, CVE-2014-0536)

Multiple flaws in flash-plugin could allow an attacker to conduct
cross-site scripting (XSS) attacks if a victim were tricked into visiting a
specially crafted web page. (CVE-2014-0531, CVE-2014-0532, CVE-2014-0533)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.378.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:27.408-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:02:50.614-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:00:30.598-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.378-1.el5" test_ref="oval:org.mitre.oval:tst:115747"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.378-1.el6" test_ref="oval:org.mitre.oval:tst:115295"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24829" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0449: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0449-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0449.html"/>
        <reference source="CESA" ref_id="CESA-2014:0449"/>
        <reference source="CVE" ref_id="CVE-2014-1518" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1518.html"/>
        <reference source="CVE" ref_id="CVE-2014-1523" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1523.html"/>
        <reference source="CVE" ref_id="CVE-2014-1524" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1524.html"/>
        <reference source="CVE" ref_id="CVE-2014-1529" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1529.html"/>
        <reference source="CVE" ref_id="CVE-2014-1530" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1530.html"/>
        <reference source="CVE" ref_id="CVE-2014-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1531.html"/>
        <reference source="CVE" ref_id="CVE-2014-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1532.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1518, CVE-2014-1524, CVE-2014-1529, CVE-2014-1531)

A use-after-free flaw was found in the way Thunderbird resolved hosts in
certain circumstances. An attacker could use this flaw to crash Thunderbird
or, potentially, execute arbitrary code with the privileges of the user
running Thunderbird. (CVE-2014-1532)

An out-of-bounds read flaw was found in the way Thunderbird decoded JPEG
images. Loading an email or a web page containing a specially crafted JPEG
image could cause Thunderbird to crash. (CVE-2014-1523)

A flaw was found in the way Thunderbird handled browser navigations through
history. An attacker could possibly use this flaw to cause the address bar
of the browser to display a web page name while loading content from an
entirely different web page, which could allow for cross-site scripting
(XSS) attacks. (CVE-2014-1530)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Bobby Holley, Carsten Book, Christoph Diehl, Gary
Kwong, Jan de Mooij, Jesse Ruderman, Nathan Froyd, Christian Holler,
Abhishek Arya, Mariusz Mlynski, moz_bug_r_a4, Nils, Tyson Smith and Jesse
Schwartzentrube as the original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.5.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.5.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:07.788-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:40.996-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:55.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:114348"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:113987"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114036"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.5.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:114360"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24812" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0918: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0918-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0918.html"/>
        <reference source="CESA" ref_id="CESA-2014:0918"/>
        <reference source="CVE" ref_id="CVE-2014-1547" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1547.html"/>
        <reference source="CVE" ref_id="CVE-2014-1555" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1555.html"/>
        <reference source="CVE" ref_id="CVE-2014-1556" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1556.html"/>
        <reference source="CVE" ref_id="CVE-2014-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1557.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1547, CVE-2014-1555, CVE-2014-1556, CVE-2014-1557)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Christian Holler, David Keeler, Byron Campen, Jethro
Beekman, Patrick Cozzi, and Mozilla community member John as the original
reporters of these issues.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.7.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.7.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:01:13.375-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:02:49.553-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:00:28.841-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:116050"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:116162"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:116061"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.7.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:116004"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24802" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0561: curl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0561-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0561.html"/>
        <reference source="CESA" ref_id="CESA-2014:0561"/>
        <reference source="CVE" ref_id="CVE-2014-0015" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0015.html"/>
        <reference source="CVE" ref_id="CVE-2014-0138" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0138.html"/>
        <description>cURL provides the libcurl library and a command line tool for downloading
files from servers using various protocols, including HTTP, FTP, and LDAP.

It was found that libcurl could incorrectly reuse existing connections for
requests that should have used different or no authentication credentials,
when using one of the following protocols: HTTP(S) with NTLM
authentication, LDAP(S), SCP, or SFTP. If an application using the libcurl
library connected to a remote server with certain authentication
credentials, this flaw could cause other requests to use those same
credentials. (CVE-2014-0015, CVE-2014-0138)

Red Hat would like to thank the cURL project for reporting these issues.
Upstream acknowledges Paras Sethia as the original reporter of
CVE-2014-0015 and Yehezkel Horowitz for discovering the security impact of
this issue, and Steve Holme as the original reporter of CVE-2014-0138.

This update also fixes the following bugs:

* Previously, the libcurl library was closing a network socket without
first terminating the SSL connection using the socket. This resulted in a
write after close and consequent leakage of memory dynamically allocated by
the SSL library. An upstream patch has been applied on libcurl to fix this
bug. As a result, the write after close no longer happens, and the SSL
library no longer leaks memory. (BZ#1092479)

* Previously, the libcurl library did not implement a non-blocking SSL
handshake, which negatively affected performance of applications based on
libcurl's multi API. To fix this bug, the non-blocking SSL handshake has
been implemented by libcurl. With this update, libcurl's multi API
immediately returns the control back to the application whenever it cannot
read/write data from/to the underlying network socket. (BZ#1092480)

* Previously, the curl package could not be rebuilt from sources due to an
expired cookie in the upstream test-suite, which runs during the build. An
upstream patch has been applied to postpone the expiration date of the
cookie, which makes it possible to rebuild the package from sources again.
(BZ#1092486)

* Previously, the libcurl library attempted to authenticate using Kerberos
whenever such an authentication method was offered by the server. This
caused problems when the server offered multiple authentication methods and
Kerberos was not the selected one. An upstream patch has been applied on
libcurl to fix this bug. Now libcurl no longer uses Kerberos authentication
if another authentication method is selected. (BZ#1096797)

All curl users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. All running
applications that use libcurl have to be restarted for this update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:20.503-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:10:54.065-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:42.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="curl is earlier than 0:7.19.7-37.el6_5.3" test_ref="oval:org.mitre.oval:tst:114394"/>
          <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_5.3" test_ref="oval:org.mitre.oval:tst:114787"/>
          <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_5.3" test_ref="oval:org.mitre.oval:tst:114569"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24794" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0509: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0509-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0509.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <description>IBM J2SE version 5.0 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0446, CVE-2014-0451, CVE-2014-2427, CVE-2014-2412,
CVE-2014-0460, CVE-2013-6629, CVE-2014-2401, CVE-2014-0453, CVE-2014-2398,
CVE-2014-1876)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM J2SE 5.0 SR16-FP6 release. All running
instances of IBM Java must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:13.676-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:39.106-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:53.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114294"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114004"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113772"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114392"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114331"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114275"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113837"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114370"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113443"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113811"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114061"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114358"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113923"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114373"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114414"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24790" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0747: python-jinja2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>python-jinja2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0747-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0747.html"/>
        <reference source="CESA" ref_id="CESA-2014:0747"/>
        <reference source="CVE" ref_id="CVE-2014-1402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1402.html"/>
        <description>Jinja2 is a template engine written in pure Python. It provides a
Django-inspired, non-XML syntax but supports inline expressions and an
optional sandboxed environment.

It was discovered that Jinja2 did not properly handle bytecode cache files
stored in the system's temporary directory. A local attacker could use this
flaw to alter the output of an application using Jinja2 and
FileSystemBytecodeCache, and potentially execute arbitrary code with the
privileges of that application. (CVE-2014-1402)

All python-jinja2 users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. For the update to
take effect, all applications using python-jinja2 must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T17:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:29.468-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:28.554-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:47.607-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="python-jinja2 is earlier than 0:2.2.1-2.el6_5" test_ref="oval:org.mitre.oval:tst:115390"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24789" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0496: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0496-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0496.html"/>
        <reference source="CVE" ref_id="CVE-2014-0510" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0510.html"/>
        <reference source="CVE" ref_id="CVE-2014-0516" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0516.html"/>
        <reference source="CVE" ref_id="CVE-2014-0517" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0517.html"/>
        <reference source="CVE" ref_id="CVE-2014-0518" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0518.html"/>
        <reference source="CVE" ref_id="CVE-2014-0519" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0519.html"/>
        <reference source="CVE" ref_id="CVE-2014-0520" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0520.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-14,
listed in the References section.

Multiple flaws were found in the way flash-plugin displayed certain SWF
content. An attacker could use these flaws to create a specially crafted
SWF file that would cause flash-plugin to crash or, potentially, execute
arbitrary code when the victim loaded a page containing the malicious SWF
content. (CVE-2014-0510, CVE-2014-0517, CVE-2014-0518, CVE-2014-0519,
CVE-2014-0520)

A flaw in flash-plugin could allow an attacker to bypass the same-origin
policy. (CVE-2014-0516)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.359.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:09.431-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:38.612-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:52.746-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.359-1.el5" test_ref="oval:org.mitre.oval:tst:114364"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.359-1.el6" test_ref="oval:org.mitre.oval:tst:113835"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24723" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0413: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0413-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0413.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6954" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6954.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0432.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0448.html"/>
        <reference source="CVE" ref_id="CVE-2014-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0449.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0454" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0454.html"/>
        <reference source="CVE" ref_id="CVE-2014-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0455.html"/>
        <reference source="CVE" ref_id="CVE-2014-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0456.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0459.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2397" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2397.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2402.html"/>
        <reference source="CVE" ref_id="CVE-2014-2403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2403.html"/>
        <reference source="CVE" ref_id="CVE-2014-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2409.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2413" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2413.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2420.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2422.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <reference source="CVE" ref_id="CVE-2014-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2428.html"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:07:59.673-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:28.442-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:26.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113900"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113949"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113941"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113976"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113955"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113612"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113277"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113802"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113525"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113785"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113074"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113657"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24718" version="9" class="patch">
      <metadata>
        <title>RHSA-2014:0376: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0376-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0160" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0160.html"/>
        <reference source="CESA-2014:0376" ref_id="CESA-2014:0376" ref_url="http://lists.centos.org/pipermail/centos-announce/2014-April/020249.html"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

An information disclosure flaw was found in the way OpenSSL handled TLS and
DTLS Heartbeat Extension packets. A malicious TLS or DTLS client or server
could send a specially crafted TLS or DTLS Heartbeat packet to disclose a
limited portion of memory per request from a connected client or server.
Note that the disclosed portions of memory could potentially include
sensitive information such as private keys. (CVE-2014-0160)

Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges Neel Mehta of Google Security as the original
reporter.

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-11T11:46:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-23T10:26:43.786-04:00">DRAFT</status_change>
            <status_change date="2014-05-12T04:01:00.372-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:21.297-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24718 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:39.356-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:40.272-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24718 - Removed CentOS 6 platform as it is part of oval:org.mitre.oval:def:24324." date="2014-12-05T19:22:00.950-05:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2014-12-05T19:27:33.324-05:00">INTERIM</status_change>
            <status_change date="2014-12-22T04:00:06.655-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24718 - CentOS criteria were added where necessary, descriptions were shortened." date="2015-03-23T14:40:00.799-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-03-23T14:45:52.452-04:00">INTERIM</status_change>
            <status_change date="2015-04-13T04:00:05.602-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 and CentOS Linux 6 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:113696"/>
            <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:113554"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:113590"/>
            <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:113774"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="openssl-debuginfo is earlier than 0:1.0.1e-16.el6_5.7" test_ref="oval:org.mitre.oval:tst:137833"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24670" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0742: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0742-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0742.html"/>
        <reference source="CESA" ref_id="CESA-2014:0742"/>
        <reference source="CVE" ref_id="CVE-2014-1533" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1533.html"/>
        <reference source="CVE" ref_id="CVE-2014-1538" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1538.html"/>
        <reference source="CVE" ref_id="CVE-2014-1541" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1541.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes
Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,
Abhishek Arya, and Nils as the original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.6.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.6.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T17:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:34.219-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:25.793-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:42.146-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:115597"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:115066"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:115511"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.6.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:115386"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24666" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0406: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0406-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0406.html"/>
        <reference source="CESA" ref_id="CESA-2014:0406"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0454" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0454.html"/>
        <reference source="CVE" ref_id="CVE-2014-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0455.html"/>
        <reference source="CVE" ref_id="CVE-2014-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0456.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0459.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2397" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2397.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2402.html"/>
        <reference source="CVE" ref_id="CVE-2014-2403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2403.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2413" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2413.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0455, CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, Security, Sound, and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to bypass
certain Java sandbox restrictions. (CVE-2014-2412, CVE-2014-0451,
CVE-2014-0458, CVE-2014-2423, CVE-2014-0452, CVE-2014-2414, CVE-2014-2402,
CVE-2014-0446, CVE-2014-2413, CVE-2014-0454, CVE-2014-2427, CVE-2014-0459)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:07:54.092-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:27.399-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:01:22.435-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.55-2.4.7.1.el6_5" test_ref="oval:org.mitre.oval:tst:113828"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.55-2.4.7.1.el6_5" test_ref="oval:org.mitre.oval:tst:113713"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.55-2.4.7.1.el6_5" test_ref="oval:org.mitre.oval:tst:113964"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.55-2.4.7.1.el6_5" test_ref="oval:org.mitre.oval:tst:114042"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.55-2.4.7.1.el6_5" test_ref="oval:org.mitre.oval:tst:114053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24650" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0447: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0447-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0447.html"/>
        <reference source="CVE" ref_id="CVE-2014-0515" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0515.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes one vulnerability in Adobe Flash Player. This
vulnerability is detailed in the Adobe Security Bulletin APSB14-13, listed
in the References section.

A flaw was found in the way flash-plugin displayed certain SWF content. An
attacker could use this flaw to create a specially crafted SWF file that
would cause flash-plugin to crash or, potentially, execute arbitrary code
when the victim loaded a page containing the malicious SWF content.
(CVE-2014-0515)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.356.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:12.471-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:20.303-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:36.113-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el5" test_ref="oval:org.mitre.oval:tst:114008"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:11.2.202.356-1.el6" test_ref="oval:org.mitre.oval:tst:114013"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24614" version="4" class="patch" deprecated="true">
      <metadata>
        <title>DEPRECATED: RHSA-2014:0889: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0889-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0889.html"/>
        <reference source="CESA" ref_id="CESA-2014:0889"/>
        <reference source="CVE" ref_id="CVE-2014-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2483.html"/>
        <reference source="CVE" ref_id="CVE-2014-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2490.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4216.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4221" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4221.html"/>
        <reference source="CVE" ref_id="CVE-2014-4223" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4223.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4266" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4266.html"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

It was discovered that the Hotspot component in OpenJDK did not properly
verify bytecode from the class files. An untrusted Java application or
applet could possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-4216, CVE-2014-4219)

A format string flaw was discovered in the Hotspot component event logger
in OpenJDK. An untrusted Java application or applet could use this flaw to
crash the Java Virtual Machine or, potentially, execute arbitrary code with
the privileges of the Java Virtual Machine. (CVE-2014-2490)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-4223,
CVE-2014-4262, CVE-2014-2483)

Multiple flaws were discovered in the JMX, Libraries, Security, and
Serviceability components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2014-4209, CVE-2014-4218, CVE-2014-4221, CVE-2014-4252, CVE-2014-4266)

It was discovered that the RSA algorithm in the Security component in
OpenJDK did not sufficiently perform blinding while performing operations
that were using private keys. An attacker able to measure timing
differences of those operations could possibly leak information about the
used keys. (CVE-2014-4244)

The Diffie-Hellman (DH) key exchange algorithm implementation in the
Security component in OpenJDK failed to validate public DH parameters
properly. This could cause OpenJDK to accept and use weak parameters,
allowing an attacker to recover the negotiated key. (CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-28T15:03:57">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-29T19:00:50.046-04:00">DRAFT</status_change>
            <status_change date="2014-08-18T04:02:34.036-04:00">INTERIM</status_change>
            <status_change date="2014-09-08T04:00:15.093-04:00">ACCEPTED</status_change>
            <modified comment="deprecated due to duplicate Definition" date="2015-02-11T18:29:50.267-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-11T18:29:50.267-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el6_5" test_ref="oval:org.mitre.oval:tst:116147"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el6_5" test_ref="oval:org.mitre.oval:tst:115982"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el6_5" test_ref="oval:org.mitre.oval:tst:116030"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el6_5" test_ref="oval:org.mitre.oval:tst:116139"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el6_5" test_ref="oval:org.mitre.oval:tst:116095"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115519"/>
            <criterion comment="java-1.7.0-openjdk-accessibility is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115782"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115867"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:116052"/>
            <criterion comment="java-1.7.0-openjdk-headless is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:116039"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115985"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115765"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24577" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0475: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0475-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0475.html"/>
        <reference source="CESA" ref_id="CESA-2014:0475"/>
        <reference source="CVE" ref_id="CVE-2013-6383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6383.html"/>
        <reference source="CVE" ref_id="CVE-2014-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0077.html"/>
        <reference source="CVE" ref_id="CVE-2014-2523" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2523.html"/>
        <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* A flaw was found in the way the Linux kernel's netfilter connection
tracking implementation for Datagram Congestion Control Protocol (DCCP)
packets used the skb_header_pointer() function. A remote attacker could use
this flaw to send a specially crafted DCCP packet to crash the system or,
potentially, escalate their privileges on the system. (CVE-2014-2523,
Important)

* A flaw was found in the way the Linux kernel's Adaptec RAID controller
(aacraid) checked permissions of compat IOCTLs. A local attacker could use
this flaw to bypass intended security restrictions. (CVE-2013-6383,
Moderate)

* A flaw was found in the way the handle_rx() function handled large
network packets when mergeable buffers were disabled. A privileged guest
user could use this flaw to crash the host or corrupt QEMU process memory
on the host, which could potentially result in arbitrary code execution on
the host with the privileges of the QEMU process. (CVE-2014-0077, Moderate)

The CVE-2014-0077 issue was discovered by Michael S. Tsirkin of Red Hat.

This update also fixes several bugs. Documentation for these changes will
be available shortly from the Technical Notes document linked to in the
References section.

All kernel users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The system must be
rebooted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:13.090-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:01:01.735-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:24.750-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="python-perf is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:113630"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:114289"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:114362"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:113901"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:114335"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:114378"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:114287"/>
          <criterion comment="kernel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:114069"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:114366"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:114291"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:114319"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:113695"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.17.1.el6" test_ref="oval:org.mitre.oval:tst:113389"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24557" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0414: java-1.6.0-sun security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0414-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0414.html"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2437.html"/>
        <reference source="CVE" ref_id="CVE-2013-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2442.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2445.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2451.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2461" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2461.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2464.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2466" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2466.html"/>
        <reference source="CVE" ref_id="CVE-2013-2468" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2468.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <reference source="CVE" ref_id="CVE-2013-3743" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3743.html"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5776.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5787.html"/>
        <reference source="CVE" ref_id="CVE-2013-5789" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5789.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5801.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5812" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5812.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5818" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5818.html"/>
        <reference source="CVE" ref_id="CVE-2013-5819" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5819.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5824" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5824.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5831" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5831.html"/>
        <reference source="CVE" ref_id="CVE-2013-5832" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5832.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5843" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5843.html"/>
        <reference source="CVE" ref_id="CVE-2013-5848" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5848.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <reference source="CVE" ref_id="CVE-2013-5852" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5852.html"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5887" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5887.html"/>
        <reference source="CVE" ref_id="CVE-2013-5888" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5888.html"/>
        <reference source="CVE" ref_id="CVE-2013-5889" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5889.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5898" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5898.html"/>
        <reference source="CVE" ref_id="CVE-2013-5899" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5899.html"/>
        <reference source="CVE" ref_id="CVE-2013-5902" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5902.html"/>
        <reference source="CVE" ref_id="CVE-2013-5905" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5905.html"/>
        <reference source="CVE" ref_id="CVE-2013-5906" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5906.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6954" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6954.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0375" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0375.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0387" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0387.html"/>
        <reference source="CVE" ref_id="CVE-2014-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0403.html"/>
        <reference source="CVE" ref_id="CVE-2014-0410" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0410.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0415.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0417.html"/>
        <reference source="CVE" ref_id="CVE-2014-0418" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0418.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0424.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0449.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0456.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2403.html"/>
        <reference source="CVE" ref_id="CVE-2014-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2409.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2420.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <reference source="CVE" ref_id="CVE-2014-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2428.html"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory pages, listed in the References section.
(CVE-2013-1500, CVE-2013-1571, CVE-2013-2407, CVE-2013-2412, CVE-2013-2437,
CVE-2013-2442, CVE-2013-2443, CVE-2013-2444, CVE-2013-2445, CVE-2013-2446,
CVE-2013-2447, CVE-2013-2448, CVE-2013-2450, CVE-2013-2451, CVE-2013-2452,
CVE-2013-2453, CVE-2013-2454, CVE-2013-2455, CVE-2013-2456, CVE-2013-2457,
CVE-2013-2459, CVE-2013-2461, CVE-2013-2463, CVE-2013-2464, CVE-2013-2465,
CVE-2013-2466, CVE-2013-2468, CVE-2013-2469, CVE-2013-2470, CVE-2013-2471,
CVE-2013-2472, CVE-2013-2473, CVE-2013-3743, CVE-2013-3829, CVE-2013-4002,
CVE-2013-5772, CVE-2013-5774, CVE-2013-5776, CVE-2013-5778, CVE-2013-5780,
CVE-2013-5782, CVE-2013-5783, CVE-2013-5784, CVE-2013-5787, CVE-2013-5789,
CVE-2013-5790, CVE-2013-5797, CVE-2013-5801, CVE-2013-5802, CVE-2013-5803,
CVE-2013-5804, CVE-2013-5809, CVE-2013-5812, CVE-2013-5814, CVE-2013-5817,
CVE-2013-5818, CVE-2013-5819, CVE-2013-5820, CVE-2013-5823, CVE-2013-5824,
CVE-2013-5825, CVE-2013-5829, CVE-2013-5830, CVE-2013-5831, CVE-2013-5832,
CVE-2013-5840, CVE-2013-5842, CVE-2013-5843, CVE-2013-5848, CVE-2013-5849,
CVE-2013-5850, CVE-2013-5852, CVE-2013-5878, CVE-2013-5884, CVE-2013-5887,
CVE-2013-5888, CVE-2013-5889, CVE-2013-5896, CVE-2013-5898, CVE-2013-5899,
CVE-2013-5902, CVE-2013-5905, CVE-2013-5906, CVE-2013-5907, CVE-2013-5910,
CVE-2013-6629, CVE-2013-6954, CVE-2014-0368, CVE-2014-0373, CVE-2014-0375,
CVE-2014-0376, CVE-2014-0387, CVE-2014-0403, CVE-2014-0410, CVE-2014-0411,
CVE-2014-0415, CVE-2014-0416, CVE-2014-0417, CVE-2014-0418, CVE-2014-0422,
CVE-2014-0423, CVE-2014-0424, CVE-2014-0428, CVE-2014-0429, CVE-2014-0446,
CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453, CVE-2014-0456,
CVE-2014-0457, CVE-2014-0458, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2403, CVE-2014-2409, CVE-2014-2412,
CVE-2014-2414, CVE-2014-2420, CVE-2014-2421, CVE-2014-2423, CVE-2014-2427,
CVE-2014-2428)

All users of java-1.6.0-sun are advised to upgrade to these updated
packages, which provide Oracle Java 6 Update 75 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:07:54.944-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:20.321-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:00:50.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114016"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113867"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113988"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113879"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114000"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113666"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114032"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113842"/>
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113239"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113722"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:113781"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.3.el5_10" test_ref="oval:org.mitre.oval:tst:114062"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24555" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0595: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0595-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0595.html"/>
        <reference source="CESA" ref_id="CESA-2014:0595"/>
        <reference source="CVE" ref_id="CVE-2014-3466" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3466.html"/>
        <description>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

A flaw was found in the way GnuTLS parsed session IDs from ServerHello
messages of the TLS/SSL handshake. A malicious server could use this flaw
to send an excessively long session ID value, which would trigger a buffer
overflow in a connecting TLS/SSL client application using GnuTLS, causing
the client application to crash or, possibly, execute arbitrary code.
(CVE-2014-3466)

Red Hat would like to thank GnuTLS upstream for reporting this issue.
Upstream acknowledges Joonas Kuorilehto of Codenomicon as the original
reporter.

Users of GnuTLS are advised to upgrade to these updated packages, which
correct this issue. For the update to take effect, all applications linked
to the GnuTLS library must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:21.809-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:10:23.171-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:23.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gnutls is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:114542"/>
          <criterion comment="gnutls-guile is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:114617"/>
          <criterion comment="gnutls-devel is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:114649"/>
          <criterion comment="gnutls-utils is earlier than 0:2.8.5-14.el6_5" test_ref="oval:org.mitre.oval:tst:114772"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24503" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0597: squid security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0597-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0597.html"/>
        <reference source="CESA" ref_id="CESA-2014:0597"/>
        <reference source="CVE" ref_id="CVE-2014-0128" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0128.html"/>
        <description>Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

A denial of service flaw was found in the way Squid processed certain HTTPS
requests when the SSL Bump feature was enabled. A remote attacker could
send specially crafted requests that could cause Squid to crash.
(CVE-2014-0128)

Red Hat would like to thank the Squid project for reporting this issue.
Upstream acknowledges Mathias Fischer and Fabian Hugelshofer from Open
Systems AG as the original reporters.

All squid users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the squid service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:22.737-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:10:21.402-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:21.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="squid is earlier than 7:3.1.10-20.el6_5.3" test_ref="oval:org.mitre.oval:tst:114399"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24489" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0412: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0412-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0412.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6954" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6954.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0432.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0448.html"/>
        <reference source="CVE" ref_id="CVE-2014-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0449.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0454" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0454.html"/>
        <reference source="CVE" ref_id="CVE-2014-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0455.html"/>
        <reference source="CVE" ref_id="CVE-2014-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0456.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0459.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2397" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2397.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2402.html"/>
        <reference source="CVE" ref_id="CVE-2014-2403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2403.html"/>
        <reference source="CVE" ref_id="CVE-2014-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2409.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2413" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2413.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2420.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2422.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <reference source="CVE" ref_id="CVE-2014-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2428.html"/>
        <description>Oracle Java SE version 7 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

This update fixes several vulnerabilities in the Oracle Java Runtime
Environment and the Oracle Java Software Development Kit. Further
information about these flaws can be found on the Oracle Java SE Critical
Patch Update Advisory page, listed in the References section.
(CVE-2013-6629, CVE-2013-6954, CVE-2014-0429, CVE-2014-0432, CVE-2014-0446,
CVE-2014-0448, CVE-2014-0449, CVE-2014-0451, CVE-2014-0452, CVE-2014-0453,
CVE-2014-0454, CVE-2014-0455, CVE-2014-0456, CVE-2014-0457, CVE-2014-0458,
CVE-2014-0459, CVE-2014-0460, CVE-2014-0461, CVE-2014-1876, CVE-2014-2397,
CVE-2014-2398, CVE-2014-2401, CVE-2014-2402, CVE-2014-2403, CVE-2014-2409,
CVE-2014-2412, CVE-2014-2413, CVE-2014-2414, CVE-2014-2420, CVE-2014-2421,
CVE-2014-2422, CVE-2014-2423, CVE-2014-2427, CVE-2014-2428)

All users of java-1.7.0-oracle are advised to upgrade to these updated
packages, which provide Oracle Java 7 Update 55 and resolve these issues.
All running instances of Oracle Java must be restarted for the update to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:07:57.793-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:17.577-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:00:45.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113277"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113802"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113525"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113785"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113074"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" test_ref="oval:org.mitre.oval:tst:113657"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113900"/>
            <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113949"/>
            <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113941"/>
            <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113976"/>
            <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113955"/>
            <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113612"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24488" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:0429: tomcat6 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0429-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0429.html"/>
        <reference source="CESA" ref_id="CESA-2014:0429"/>
        <reference source="CVE" ref_id="CVE-2013-4286" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4286.html"/>
        <reference source="CVE" ref_id="CVE-2013-4322" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4322.html"/>
        <reference source="CVE" ref_id="CVE-2014-0050" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0050.html"/>
        <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was found that when Tomcat processed a series of HTTP requests in which
at least one request contained either multiple content-length headers, or
one content-length header with a chunked transfer-encoding header, Tomcat
would incorrectly handle the request. A remote attacker could use this flaw
to poison a web cache, perform cross-site scripting (XSS) attacks, or
obtain sensitive information from other requests. (CVE-2013-4286)

It was discovered that the fix for CVE-2012-3544 did not properly resolve a
denial of service flaw in the way Tomcat processed chunk extensions and
trailing headers in chunked requests. A remote attacker could use this flaw
to send an excessively long request that, when processed by Tomcat, could
consume network bandwidth, CPU, and memory on the Tomcat server. Note that
chunked transfer encoding is enabled by default. (CVE-2013-4322)

A denial of service flaw was found in the way Apache Commons FileUpload
handled small-sized buffers used by MultipartStream. A remote attacker
could use this flaw to create a malformed Content-Type header for a
multipart request, causing JBoss Web to enter an infinite loop when
processing such an incoming request. (CVE-2014-0050)

All Tomcat users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. Tomcat must be
restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:08:01.643-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:17.295-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:00:44.826-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24488 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:36.902-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:20.810-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113834"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113961"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113917"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113671"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:114072"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113926"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113816"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113911"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-64.el6_5" test_ref="oval:org.mitre.oval:tst:113853"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24446" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0508: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0508-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0508.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6954" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6954.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0449.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2409.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2420.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <reference source="CVE" ref_id="CVE-2014-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2428.html"/>
        <description>IBM Java SE version 6 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0461, CVE-2014-2428, CVE-2014-0446, CVE-2014-0452,
CVE-2014-0451, CVE-2014-2423, CVE-2014-2427, CVE-2014-0458, CVE-2014-2414,
CVE-2014-2412, CVE-2014-2409, CVE-2014-0460, CVE-2013-6954, CVE-2013-6629,
CVE-2014-2401, CVE-2014-0449, CVE-2014-0453, CVE-2014-2398, CVE-2014-1876,
CVE-2014-2420)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 6 SR16 release. All running instances
of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:15.401-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:41.478-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:17.898-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114248"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114111"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114189"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113406"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113822"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113950"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113426"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114381"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114372"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114304"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114046"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114256"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114217"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114359"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114333"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24444" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0408: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0408-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0408.html"/>
        <reference source="CESA" ref_id="CESA-2014:0408"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0456.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2397" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2397.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2403.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <description>The java-1.6.0-openjdk packages provide the OpenJDK 6 Java Runtime
Environment and the OpenJDK 6 Java Software Development Kit.

An input validation flaw was discovered in the medialib library in the 2D
component. A specially crafted image could trigger Java Virtual Machine
memory corruption when processed. A remote attacker, or an untrusted Java
application or applet, could possibly use this flaw to execute arbitrary
code with the privileges of the user running the Java Virtual Machine.
(CVE-2014-0429)

Multiple flaws were discovered in the Hotspot and 2D components in OpenJDK.
An untrusted Java application or applet could use these flaws to trigger
Java Virtual Machine memory corruption and possibly bypass Java sandbox
restrictions. (CVE-2014-0456, CVE-2014-2397, CVE-2014-2421)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-0457,
CVE-2014-0461)

Multiple improper permission check issues were discovered in the AWT,
JAX-WS, JAXB, Libraries, and Sound components in OpenJDK. An untrusted Java
application or applet could use these flaws to bypass certain Java sandbox
restrictions. (CVE-2014-2412, CVE-2014-0451, CVE-2014-0458, CVE-2014-2423,
CVE-2014-0452, CVE-2014-2414, CVE-2014-0446, CVE-2014-2427)

Multiple flaws were identified in the Java Naming and Directory Interface
(JNDI) DNS client. These flaws could make it easier for a remote attacker
to perform DNS spoofing attacks. (CVE-2014-0460)

It was discovered that the JAXP component did not properly prevent access
to arbitrary files when a SecurityManager was present. This flaw could
cause a Java application using JAXP to leak sensitive information, or
affect application availability. (CVE-2014-2403)

It was discovered that the Security component in OpenJDK could leak some
timing information when performing PKCS#1 unpadding. This could possibly
lead to the disclosure of some information that was meant to be protected
by encryption. (CVE-2014-0453)

It was discovered that the fix for CVE-2013-5797 did not properly resolve
input sanitization flaws in javadoc. When javadoc documentation was
generated from an untrusted Java source code and hosted on a domain not
controlled by the code author, these issues could make it easier to perform
cross-site scripting (XSS) attacks. (CVE-2014-2398)

An insecure temporary file use flaw was found in the way the unpack200
utility created log files. A local attacker could possibly use this flaw to
perform a symbolic link attack and overwrite arbitrary files with the
privileges of the user running unpack200. (CVE-2014-1876)

This update also fixes the following bug:

* The OpenJDK update to IcedTea version 1.13 introduced a regression
related to the handling of the jdk_version_info variable. This variable was
not properly zeroed out before being passed to the Java Virtual Machine,
resulting in a memory leak in the java.lang.ref.Finalizer class.
This update fixes this issue, and memory leaks no longer occur.
(BZ#1085373)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:07:53.004-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:15.993-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:00:39.626-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113830"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113896"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114024"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:113056"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el5_10" test_ref="oval:org.mitre.oval:tst:114041"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113683"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113861"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113650"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:114057"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el6_5" test_ref="oval:org.mitre.oval:tst:113912"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24440" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0889: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0889-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0889.html"/>
        <reference source="CESA" ref_id="CESA-2014:0889"/>
        <reference source="CVE" ref_id="CVE-2014-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2483.html"/>
        <reference source="CVE" ref_id="CVE-2014-2490" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2490.html"/>
        <reference source="CVE" ref_id="CVE-2014-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4209.html"/>
        <reference source="CVE" ref_id="CVE-2014-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4216.html"/>
        <reference source="CVE" ref_id="CVE-2014-4218" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4218.html"/>
        <reference source="CVE" ref_id="CVE-2014-4219" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4219.html"/>
        <reference source="CVE" ref_id="CVE-2014-4221" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4221.html"/>
        <reference source="CVE" ref_id="CVE-2014-4223" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4223.html"/>
        <reference source="CVE" ref_id="CVE-2014-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4244.html"/>
        <reference source="CVE" ref_id="CVE-2014-4252" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4252.html"/>
        <reference source="CVE" ref_id="CVE-2014-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4262.html"/>
        <reference source="CVE" ref_id="CVE-2014-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4263.html"/>
        <reference source="CVE" ref_id="CVE-2014-4266" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-4266.html"/>
        <description>The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime
Environment and the OpenJDK 7 Java Software Development Kit.

It was discovered that the Hotspot component in OpenJDK did not properly
verify bytecode from the class files. An untrusted Java application or
applet could possibly use these flaws to bypass Java sandbox restrictions.
(CVE-2014-4216, CVE-2014-4219)

A format string flaw was discovered in the Hotspot component event logger
in OpenJDK. An untrusted Java application or applet could use this flaw to
crash the Java Virtual Machine or, potentially, execute arbitrary code with
the privileges of the Java Virtual Machine. (CVE-2014-2490)

Multiple improper permission check issues were discovered in the Libraries
component in OpenJDK. An untrusted Java application or applet could use
these flaws to bypass Java sandbox restrictions. (CVE-2014-4223,
CVE-2014-4262, CVE-2014-2483)

Multiple flaws were discovered in the JMX, Libraries, Security, and
Serviceability components in OpenJDK. An untrusted Java application or
applet could use these flaws to bypass certain Java sandbox restrictions.
(CVE-2014-4209, CVE-2014-4218, CVE-2014-4221, CVE-2014-4252, CVE-2014-4266)

It was discovered that the RSA algorithm in the Security component in
OpenJDK did not sufficiently perform blinding while performing operations
that were using private keys. An attacker able to measure timing
differences of those operations could possibly leak information about the
used keys. (CVE-2014-4244)

The Diffie-Hellman (DH) key exchange algorithm implementation in the
Security component in OpenJDK failed to validate public DH parameters
properly. This could cause OpenJDK to accept and use weak parameters,
allowing an attacker to recover the negotiated key. (CVE-2014-4263)

The CVE-2014-4262 issue was discovered by Florian Weimer of Red Hat
Product Security.

Note: If the web browser plug-in provided by the icedtea-web package was
installed, the issues exposed via Java applets could have been exploited
without user interaction if a user visited a malicious website.

All users of java-1.7.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-21T11:31:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-25T12:00:02.874-04:00">DRAFT</status_change>
            <status_change date="2014-08-11T04:00:20.696-04:00">INTERIM</status_change>
            <status_change date="2014-09-01T04:02:40.213-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el6_5" test_ref="oval:org.mitre.oval:tst:115329"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el6_5" test_ref="oval:org.mitre.oval:tst:115926"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el6_5" test_ref="oval:org.mitre.oval:tst:115958"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el6_5" test_ref="oval:org.mitre.oval:tst:115995"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el6_5" test_ref="oval:org.mitre.oval:tst:115800"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 7 or Centos 7 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115753"/>
            <criterion comment="java-1.7.0-openjdk-accessibility is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115698"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115834"/>
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115373"/>
            <criterion comment="java-1.7.0-openjdk-headless is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115715"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115814"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el7_0" test_ref="oval:org.mitre.oval:tst:115725"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24439" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:0380: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0380-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0380.html"/>
        <reference source="CVE" ref_id="CVE-2014-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0506.html"/>
        <reference source="CVE" ref_id="CVE-2014-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0507.html"/>
        <reference source="CVE" ref_id="CVE-2014-0508" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0508.html"/>
        <reference source="CVE" ref_id="CVE-2014-0509" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0509.html"/>
        <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

This update fixes multiple vulnerabilities in Adobe Flash Player. These
vulnerabilities are detailed in the Adobe Security Bulletin APSB14-09,
listed in the References section.

Two flaws were found in the way flash-plugin displayed certain SWF content.
An attacker could use these flaws to create a specially crafted SWF file
that would cause flash-plugin to crash or, potentially, execute arbitrary
code when the victim loaded a page containing the malicious SWF content.
(CVE-2014-0506, CVE-2014-0507)

A flaw in flash-plugin could allow an attacker to obtain sensitive
information if a victim were tricked into visiting a specially crafted web
page. (CVE-2014-0508)

A flaw in flash-plugin could allow an attacker to conduct cross-site
scripting (XSS) attacks if a victim were tricked into visiting a specially
crafted web page. (CVE-2014-0509)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 11.2.202.350.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-11T11:46:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-23T10:26:45.530-04:00">DRAFT</status_change>
            <status_change date="2014-05-12T04:00:54.348-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:13.168-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24439 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:41.405-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:38.088-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.350-1.el5" test_ref="oval:org.mitre.oval:tst:141011"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.350-1.el6" test_ref="oval:org.mitre.oval:tst:113518"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24407" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0513: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0513-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0513.html"/>
        <reference source="CESA" ref_id="CESA-2014:0513"/>
        <reference source="CVE" ref_id="CVE-2013-2877" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2877.html"/>
        <reference source="CVE" ref_id="CVE-2014-0191" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0191.html"/>
        <description>The libxml2 library is a development toolbox providing the implementation
of various XML standards.

It was discovered that libxml2 loaded external parameter entities even when
entity substitution was disabled. A remote attacker able to provide a
specially crafted XML file to an application linked against libxml2 could
use this flaw to conduct XML External Entity (XXE) attacks, possibly
resulting in a denial of service or an information leak on the system.
(CVE-2014-0191)

An out-of-bounds read flaw was found in the way libxml2 detected the end of
an XML file. A remote attacker could provide a specially crafted XML file
that, when processed by an application linked against libxml2, could cause
the application to crash. (CVE-2013-2877)

The CVE-2014-0191 issue was discovered by Daniel P. Berrange of Red Hat.

All libxml2 users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. The desktop must be
restarted (log out, then log back in) for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:10.458-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:36.284-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:10:13.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libxml2 is earlier than 0:2.7.6-14.el6_5.1" test_ref="oval:org.mitre.oval:tst:114443"/>
          <criterion comment="libxml2-devel is earlier than 0:2.7.6-14.el6_5.1" test_ref="oval:org.mitre.oval:tst:113930"/>
          <criterion comment="libxml2-python is earlier than 0:2.7.6-14.el6_5.1" test_ref="oval:org.mitre.oval:tst:114323"/>
          <criterion comment="libxml2-static is earlier than 0:2.7.6-14.el6_5.1" test_ref="oval:org.mitre.oval:tst:114393"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24340" version="6" class="patch">
      <metadata>
        <title>RHSA-2014:0348: xalan-j2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xalan-j2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0348-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0348.html"/>
        <reference source="CESA" ref_id="CESA-2014:0348"/>
        <reference source="CVE" ref_id="CVE-2014-0107" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0107.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-02T11:44:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-03T10:28:23.096-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:45.803-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:47.975-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24340 - 3 patches on RHEL where CentOS checks were added" date="2014-07-28T18:10:00.421-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-07-28T18:11:31.352-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:30.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112937"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112887"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112942"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:112612"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-6jpp.2" test_ref="oval:org.mitre.oval:tst:113186"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xalan-j2-demo is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113365"/>
            <criterion comment="xalan-j2-manual is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113217"/>
            <criterion comment="xalan-j2-xsltc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113295"/>
            <criterion comment="xalan-j2-javadoc is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113337"/>
            <criterion comment="xalan-j2 is earlier than 0:2.7.0-9.9.el6_5" test_ref="oval:org.mitre.oval:tst:113048"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24337" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0292: 389-ds-base security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0292-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0292.html"/>
        <reference source="CESA" ref_id="CESA-2014:0292"/>
        <reference source="CVE" ref_id="CVE-2014-0132" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0132.html"/>
        <description>The 389 Directory Server is an LDAPv3 compliant server. The base packages
include the Lightweight Directory Access Protocol (LDAP) server and
command-line utilities for server administration.

It was discovered that the 389 Directory Server did not properly handle
certain SASL-based authentication mechanisms. A user able to authenticate
to the directory using these SASL mechanisms could connect as any other
directory user, including the administrative Directory Manager account.
This could allow them to modify configuration values, as well as read and
write any data the directory holds. (CVE-2014-0132)

All 389-ds-base users are advised to upgrade to these updated packages,
which contain a backported patch to correct this issue. After installing
this update, the 389 server service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:31.499-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24337 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:47.833-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:12.380-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24337 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:35.488-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:11.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-32.el6_5" test_ref="oval:org.mitre.oval:tst:112812"/>
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-32.el6_5" test_ref="oval:org.mitre.oval:tst:113174"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-32.el6_5" test_ref="oval:org.mitre.oval:tst:112267"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24321" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0304: mutt security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mutt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0304-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0304.html"/>
        <reference source="CESA" ref_id="CESA-2014:0304"/>
        <reference source="CVE" ref_id="CVE-2014-0467" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0467.html"/>
        <description>Mutt is a text-mode mail user agent.

A heap-based buffer overflow flaw was found in the way mutt processed
certain email headers. A remote attacker could use this flaw to send an
email with specially crafted headers that, when processed, could cause mutt
to crash or, potentially, execute arbitrary code with the permissions of
the user running mutt. (CVE-2014-0467)

All mutt users are advised to upgrade to this updated package, which
contains a backported patch to correct this issue. All running instances of
mutt must be restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:31.341-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24321 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:46.777-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:11.959-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24321 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:39.880-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:10.678-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="mutt is earlier than 5:1.5.20-4.20091214hg736b6a.el6_5" test_ref="oval:org.mitre.oval:tst:113222"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24297" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0383: samba4 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0383-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0383.html"/>
        <reference source="CESA" ref_id="CESA-2014:0383"/>
        <reference source="CVE" ref_id="CVE-2012-6150" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6150.html"/>
        <reference source="CVE" ref_id="CVE-2013-4496" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4496.html"/>
        <reference source="CVE" ref_id="CVE-2013-6442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6442.html"/>
        <description>Samba is an open-source implementation of the Server Message Block (SMB) or
Common Internet File System (CIFS) protocol, which allows PC-compatible
machines to share files, printers, and other information.

It was found that certain Samba configurations did not enforce the password
lockout mechanism. A remote attacker could use this flaw to perform
password guessing attacks on Samba user accounts. Note: this flaw only
affected Samba when deployed as a Primary Domain Controller.
(CVE-2013-4496)

A flaw was found in Samba's "smbcacls" command, which is used to set or get
ACLs on SMB file shares. Certain command line options of this command would
incorrectly remove an ACL previously applied on a file or a directory,
leaving the file or directory without the intended ACL. (CVE-2013-6442)

A flaw was found in the way the pam_winbind module handled configurations
that specified a non-existent group as required. An authenticated user
could possibly use this flaw to gain access to a service using pam_winbind
in its PAM configuration when group restriction was intended for access to
the service. (CVE-2012-6150)

Red Hat would like to thank the Samba project for reporting CVE-2013-4496
and CVE-2013-6442, and Sam Richardson for reporting CVE-2012-6150.
Upstream acknowledges Andrew Bartlett as the original reporter of
CVE-2013-4496, and Noel Power as the original reporter of CVE-2013-6442.

All users of Samba are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the smb service will be restarted automatically.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-11T11:46:55">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-23T10:26:45.210-04:00">DRAFT</status_change>
            <status_change date="2014-05-12T04:00:45.106-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:11.295-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="samba4-python is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113088"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113311"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113776"/>
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113223"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113764"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113308"/>
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113542"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:112905"/>
          <criterion comment="samba4 is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113799"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113658"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113001"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113385"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113527"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-61.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:113457"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24293" version="27" class="patch">
      <metadata>
        <title>RHSA-2014:0310: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0310-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0310.html"/>
        <reference source="CESA" ref_id="CESA-2014:0310"/>
        <reference source="CVE" ref_id="CVE-2014-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1493.html"/>
        <reference source="CVE" ref_id="CVE-2014-1497" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1497.html"/>
        <reference source="CVE" ref_id="CVE-2014-1505" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1505.html"/>
        <reference source="CVE" ref_id="CVE-2014-1508" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1508.html"/>
        <reference source="CVE" ref_id="CVE-2014-1509" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1509.html"/>
        <reference source="CVE" ref_id="CVE-2014-1510" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1510.html"/>
        <reference source="CVE" ref_id="CVE-2014-1511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1511.html"/>
        <reference source="CVE" ref_id="CVE-2014-1512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1512.html"/>
        <reference source="CVE" ref_id="CVE-2014-1513" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1513.html"/>
        <reference source="CVE" ref_id="CVE-2014-1514" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1514.html"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)

Several information disclosure flaws were found in the way Firefox
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Firefox to crash. (CVE-2014-1497,
CVE-2014-1508, CVE-2014-1505)

A memory corruption flaw was found in the way Firefox rendered certain PDF
files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Firefox or, potentially, execute
arbitrary code with the privileges of the user running Firefox.
(CVE-2014-1509)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.4.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.4.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:33.713-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24293 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:44.438-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:10.760-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24293 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:37.186-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:09.689-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:112878"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="firefox is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:113033"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.4.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:113576"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.4.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:113902"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24262" version="4" class="patch">
      <metadata>
        <title>RHSA-2014:0741: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 7</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <platform>CentOS Linux 7</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0741-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0741.html"/>
        <reference source="CESA" ref_id="CESA-2014:0741"/>
        <reference source="CVE" ref_id="CVE-2014-1533" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1533.html"/>
        <reference source="CVE" ref_id="CVE-2014-1538" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1538.html"/>
        <reference source="CVE" ref_id="CVE-2014-1541" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1541.html"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2014-1533, CVE-2014-1538, CVE-2014-1541)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Gary Kwong, Christoph Diehl, Christian Holler, Hannes
Verschore, Jan de Mooij, Ryan VanderMeulen, Jeff Walden, Kyle Huey,
Abhishek Arya, and Nils as the original reporters of these issues.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 24.6.0 ESR. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 24.6.0 ESR, which corrects these issues. After installing
the update, Firefox must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T17:22:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:32.348-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:17.168-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24262 - 3 patches on RHEL where CentOS checks were added" date="2014-07-28T18:10:00.421-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-08-18T04:02:29.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.6.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:115278"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.6.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:115251"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="firefox is earlier than 0:24.6.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:114950"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.6.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:114602"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria comment="Redhat 7 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 7" definition_ref="oval:org.mitre.oval:def:24953"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115498"/>
            <criterion comment="xulrunner-devel is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115120"/>
            <criterion comment="xulrunner is earlier than 0:24.6.0-1.el7_0" test_ref="oval:org.mitre.oval:tst:115439"/>
          </criteria>
        </criteria>
        <criteria comment="Centos 7 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 7.x" definition_ref="oval:org.mitre.oval:def:24773"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:24.6.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:116069"/>
            <criterion comment="xulrunner is earlier than 0:24.6.0-1.el7.centos" test_ref="oval:org.mitre.oval:tst:115672"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24953" version="3" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 7</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:7"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 7.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-02T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-07-07T16:13:29.153-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:42.013-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:58.393-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 7 is installed" test_ref="oval:org.mitre.oval:tst:115398"/>
        <criterion negate="true" comment="Oracle Linux 7.x is installed" test_ref="oval:org.mitre.oval:tst:115342"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24773" version="3" class="inventory">
      <metadata>
        <title>The operating system installed on the system is CentOS Linux 7.x</title>
        <affected family="unix">
          <platform>CentOS Linux 7</platform>
        </affected>
        <reference ref_id="cpe:/o:centos:centos:7" source="CPE"/>
        <description>The operating system installed on the system is CentOS Linux 7.x</description>
        <oval_repository>
          <dates>
            <submitted date="2014-07-08T08:31:03">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </submitted>
            <status_change date="2014-07-09T11:48:47.285-04:00">DRAFT</status_change>
            <status_change date="2014-07-28T04:00:27.738-04:00">INTERIM</status_change>
            <status_change date="2014-08-18T04:02:46.796-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Unix family" test_ref="oval:org.mitre.oval:tst:4424"/>
        <criterion comment="CentOS Linux 7.x is installed" test_ref="oval:org.mitre.oval:tst:115369"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24260" version="7" class="patch">
      <metadata>
        <title>RHSA-2014:0330: samba and samba3x security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0330-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0330.html"/>
        <reference source="CESA" ref_id="CESA-2014:0330"/>
        <reference source="CVE" ref_id="CVE-2012-6150" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6150.html"/>
        <reference source="CVE" ref_id="CVE-2013-4496" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4496.html"/>
        <description>Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-02T11:44:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-03T10:28:24.911-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:41.476-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:42.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:112514"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:112992"/>
            <criterion comment="samba3x is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113193"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113084"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113155"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113272"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113128"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.139.el5_10" test_ref="oval:org.mitre.oval:tst:113304"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-swat is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112639"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112379"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112720"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112784"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112354"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113240"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113361"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113289"/>
            <criterion comment="samba is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113058"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112481"/>
            <criterion comment="samba-common is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:112759"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-168.el6_5" test_ref="oval:org.mitre.oval:tst:113037"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24219" version="11" class="patch">
      <metadata>
        <title>RHSA-2014:0328: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0328-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0328.html"/>
        <reference source="CESA" ref_id="CESA-2014:0328"/>
        <reference source="CVE" ref_id="CVE-2013-1860" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1860.html"/>
        <reference source="CVE" ref_id="CVE-2014-0055" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0055.html"/>
        <reference source="CVE" ref_id="CVE-2014-0069" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0069.html"/>
        <reference source="CVE" ref_id="CVE-2014-0101" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0101.html"/>
        <description>The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-02T11:44:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-03T10:28:27.699-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:39.306-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:38.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113310"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113324"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113122"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113281"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113107"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113302"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113341"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113314"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:112903"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113176"/>
          <criterion comment="kernel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113045"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:112796"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.11.2.el6" test_ref="oval:org.mitre.oval:tst:113194"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24162" version="18" class="patch">
      <metadata>
        <title>RHSA-2014:0196: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0196-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0196.html"/>
        <reference source="CVE" ref_id="CVE-2014-0498" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0498.html"/>
        <reference source="CVE" ref_id="CVE-2014-0499" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0499.html"/>
        <reference source="CVE" ref_id="CVE-2014-0502" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0502.html"/>
        <description>Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK &amp; Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:48.730-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:49.317-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24162 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:35.401-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24162 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:40.626-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:36.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.341-1.el5" test_ref="oval:org.mitre.oval:tst:140799"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.341-1.el6" test_ref="oval:org.mitre.oval:tst:112925"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24155" version="7" class="patch">
      <metadata>
        <title>RHSA-2014:0185: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0185-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0185.html"/>
        <reference source="CESA" ref_id="CESA-2014:0185"/>
        <reference source="CVE" ref_id="CVE-2013-6466" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6466.html"/>
        <description>Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:48.395-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:48.909-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24155 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:34.853-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24155 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:40.060-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:05.121-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:112679"/>
            <criterion comment="openswan is earlier than 0:2.6.32-7.3.el5_10" test_ref="oval:org.mitre.oval:tst:112172"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan-doc is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:112726"/>
            <criterion comment="openswan is earlier than 0:2.6.32-27.2.el6_5" test_ref="oval:org.mitre.oval:tst:112948"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24133" version="34" class="patch">
      <metadata>
        <title>RHSA-2014:0222: libtiff security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0222-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0222.html"/>
        <reference source="CESA" ref_id="CESA-2014:0222"/>
        <reference source="CVE" ref_id="CVE-2010-2596" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2596.html"/>
        <reference source="CVE" ref_id="CVE-2013-1960" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1960.html"/>
        <reference source="CVE" ref_id="CVE-2013-1961" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1961.html"/>
        <reference source="CVE" ref_id="CVE-2013-4231" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4231.html"/>
        <reference source="CVE" ref_id="CVE-2013-4232" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4232.html"/>
        <reference source="CVE" ref_id="CVE-2013-4243" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4243.html"/>
        <reference source="CVE" ref_id="CVE-2013-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4244.html"/>
        <description>The LZW decompressor in the gif2tiff tool in libtiff 4.0.3 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:51.524-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:47.979-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24133 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:33.969-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24133 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:32.911-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:04.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libtiff is earlier than 0:3.9.4-10.el6_5" test_ref="oval:org.mitre.oval:tst:112900"/>
          <criterion comment="libtiff-static is earlier than 0:3.9.4-10.el6_5" test_ref="oval:org.mitre.oval:tst:112957"/>
          <criterion comment="libtiff-devel is earlier than 0:3.9.4-10.el6_5" test_ref="oval:org.mitre.oval:tst:112980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24127" version="21" class="patch">
      <metadata>
        <title>RHSA-2014:0211: postgresql84 and postgresql security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0211-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0211.html"/>
        <reference source="CESA" ref_id="CESA-2014:0211"/>
        <reference source="CVE" ref_id="CVE-2014-0060" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0060.html"/>
        <reference source="CVE" ref_id="CVE-2014-0061" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0061.html"/>
        <reference source="CVE" ref_id="CVE-2014-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0062.html"/>
        <reference source="CVE" ref_id="CVE-2014-0063" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0063.html"/>
        <reference source="CVE" ref_id="CVE-2014-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0064.html"/>
        <reference source="CVE" ref_id="CVE-2014-0065" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0065.html"/>
        <reference source="CVE" ref_id="CVE-2014-0066" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0066.html"/>
        <description>PostgreSQL is an advanced object-relational database management system
(DBMS).

Multiple stack-based buffer overflow flaws were found in the date/time
implementation of PostgreSQL. An authenticated database user could provide
a specially crafted date/time value that, when processed, could cause
PostgreSQL to crash or, potentially, execute arbitrary code with the
permissions of the user running PostgreSQL. (CVE-2014-0063)

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in various type input functions in PostgreSQL. An authenticated
database user could possibly use these flaws to crash PostgreSQL or,
potentially, execute arbitrary code with the permissions of the user
running PostgreSQL. (CVE-2014-0064)

Multiple potential buffer overflow flaws were found in PostgreSQL.
An authenticated database user could possibly use these flaws to crash
PostgreSQL or, potentially, execute arbitrary code with the permissions of
the user running PostgreSQL. (CVE-2014-0065)

It was found that granting an SQL role to a database user in a PostgreSQL
database without specifying the "ADMIN" option allowed the grantee to
remove other users from their granted role. An authenticated database user
could use this flaw to remove a user from an SQL role which they were
granted access to. (CVE-2014-0060)

A flaw was found in the validator functions provided by PostgreSQL's
procedural languages (PLs). An authenticated database user could possibly
use this flaw to escalate their privileges. (CVE-2014-0061)

A race condition was found in the way the CREATE INDEX command performed
multiple independent lookups of a table that had to be indexed. An
authenticated database user could possibly use this flaw to escalate their
privileges. (CVE-2014-0062)

It was found that the chkpass extension of PostgreSQL did not check the
return value of the crypt() function. An authenticated database user could
possibly use this flaw to crash PostgreSQL via a null pointer dereference.
(CVE-2014-0066)

Red Hat would like to thank the PostgreSQL project for reporting these
issues. Upstream acknowledges Noah Misch as the original reporter of
CVE-2014-0060 and CVE-2014-0063, Heikki Linnakangas and Noah Misch as the
original reporters of CVE-2014-0064, Peter Eisentraut and Jozef Mlich as
the original reporters of CVE-2014-0065, Andres Freund as the original
reporter of CVE-2014-0061, Robert Haas and Andres Freund as the original
reporters of CVE-2014-0062, and Honza Horak and Bruce Momjian as the
original reporters of CVE-2014-0066.

These updated packages upgrade PostgreSQL to version 8.4.20, which fixes
these issues as well as several non-security issues. Refer to the
PostgreSQL Release Notes for a full list of changes:

http://www.postgresql.org/docs/8.4/static/release-8-4-19.html
http://www.postgresql.org/docs/8.4/static/release-8-4-20.html

All PostgreSQL users are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. If the postgresql
service is running, it will be automatically restarted after installing
this update.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:50.989-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:06:47.290-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24127 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:33.401-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24127 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:39.152-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:02.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql84-python is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112803"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112698"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112714"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112684"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112347"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112782"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112800"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112943"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112658"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112909"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112076"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.20-1.el5_10" test_ref="oval:org.mitre.oval:tst:112596"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql-contrib is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112960"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112717"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112744"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112591"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112749"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112856"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112494"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112907"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112462"/>
            <criterion comment="postgresql is earlier than 0:8.4.20-1.el6_5" test_ref="oval:org.mitre.oval:tst:112809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24104" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0420: qemu-kvm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0420-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0420.html"/>
        <reference source="CESA" ref_id="CESA-2014:0420"/>
        <reference source="CVE" ref_id="CVE-2014-0142" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0142.html"/>
        <reference source="CVE" ref_id="CVE-2014-0143" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0143.html"/>
        <reference source="CVE" ref_id="CVE-2014-0144" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0144.html"/>
        <reference source="CVE" ref_id="CVE-2014-0145" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0145.html"/>
        <reference source="CVE" ref_id="CVE-2014-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0146.html"/>
        <reference source="CVE" ref_id="CVE-2014-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0147.html"/>
        <reference source="CVE" ref_id="CVE-2014-0148" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0148.html"/>
        <reference source="CVE" ref_id="CVE-2014-0150" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0150.html"/>
        <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. The qemu-kvm package provides the
user-space component for running virtual machines using KVM.

Multiple integer overflow, input validation, logic error, and buffer
overflow flaws were discovered in various QEMU block drivers. An attacker
able to modify a disk image file loaded by a guest could use these flaws to
crash the guest, or corrupt QEMU process memory on the host, potentially
resulting in arbitrary code execution on the host with the privileges of
the QEMU process. (CVE-2014-0143, CVE-2014-0144, CVE-2014-0145,
CVE-2014-0147)

A buffer overflow flaw was found in the way the virtio_net_handle_mac()
function of QEMU processed guest requests to update the table of MAC
addresses. A privileged guest user could use this flaw to corrupt QEMU
process memory on the host, potentially resulting in arbitrary code
execution on the host with the privileges of the QEMU process.
(CVE-2014-0150)

A divide-by-zero flaw was found in the seek_to_sector() function of the
parallels block driver in QEMU. An attacker able to modify a disk image
file loaded by a guest could use this flaw to crash the guest.
(CVE-2014-0142)

A NULL pointer dereference flaw was found in the QCOW2 block driver in
QEMU. An attacker able to modify a disk image file loaded by a guest could
use this flaw to crash the guest. (CVE-2014-0146)

It was found that the block driver for Hyper-V VHDX images did not
correctly calculate BAT (Block Allocation Table) entries due to a missing
bounds check. An attacker able to modify a disk image file loaded by a
guest could use this flaw to crash the guest. (CVE-2014-0148)

The CVE-2014-0143 issues were discovered by Kevin Wolf and Stefan Hajnoczi
of Red Hat, the CVE-2014-0144 issues were discovered by Fam Zheng, Jeff
Cody, Kevin Wolf, and Stefan Hajnoczi of Red Hat, the CVE-2014-0145 issues
were discovered by Stefan Hajnoczi of Red Hat, the CVE-2014-0150 issue was
discovered by Michael S. Tsirkin of Red Hat, the CVE-2014-0142,
CVE-2014-0146, and CVE-2014-0147 issues were discovered by Kevin Wolf of
Red Hat, and the CVE-2014-0148 issue was discovered by Jeff Cody of
Red Hat.

All qemu-kvm users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, shut down all running virtual machines. Once all virtual machines
have shut down, start them again for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-24T11:24:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-30T15:08:01.093-04:00">DRAFT</status_change>
            <status_change date="2014-05-19T04:00:11.499-04:00">INTERIM</status_change>
            <status_change date="2014-06-09T04:00:28.711-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:113919"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:113840"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:114025"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.8" test_ref="oval:org.mitre.oval:tst:113998"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24089" version="4" class="patch">
      <metadata>
        <title>RHSA-2014:0431: virt-viewer bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>virt-viewer</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0431-02" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0431.html"/>
        <reference source="CEBA" ref_id="CEBA-2014:0431"/>
        <description>The virt-viewer packages provide Virtual Machine Viewer, which is a lightweight interface for interacting with the graphical display of a virtualized guest. Virtual Machine Viewer uses libvirt and is intended as a replacement for traditional VNC or SPICE clients.

This update fixes the following bug: 

* Prior to this update, Spice determined the scaling of windows incorrectly by using the original desktop size instead of the host screen size. As a consequence, when a guest window was open in Spice, the screen could under some circumstances become blurry. With this update, the guest window scaling has been fixed and this problem no longer occurs. (BZ#1081376)

Users of virt-viewer are advised to upgrade to these updated packages, which fix this bug.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:17.771-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:24089 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-30T04:10:02.353-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:08.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="virt-viewer is earlier than 0:0.5.6-8.el6_5.1" test_ref="oval:org.mitre.oval:tst:114253"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24067" version="5" class="patch">
      <metadata>
        <title>RHSA-2014:0370: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0370-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0370.html"/>
        <reference source="CESA" ref_id="CESA-2014:0370"/>
        <reference source="CVE" ref_id="CVE-2013-6438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6438.html"/>
        <reference source="CVE" ref_id="CVE-2014-0098" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0098.html"/>
        <description>The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-07T11:36:17">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-10T08:40:40.424-04:00">DRAFT</status_change>
            <status_change date="2014-04-28T04:07:15.076-04:00">INTERIM</status_change>
            <status_change date="2014-05-19T04:00:10.887-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-tools is earlier than 0:2.2.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:113413"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:113327"/>
            <criterion comment="httpd is earlier than 0:2.2.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:113079"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:113330"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-30.el6_5" test_ref="oval:org.mitre.oval:tst:113273"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-tools is earlier than 0:2.2.15-30.el6.centos" test_ref="oval:org.mitre.oval:tst:112757"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-30.el6.centos" test_ref="oval:org.mitre.oval:tst:112517"/>
            <criterion comment="httpd is earlier than 0:2.2.15-30.el6.centos" test_ref="oval:org.mitre.oval:tst:113096"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-30.el6.centos" test_ref="oval:org.mitre.oval:tst:113373"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-30.el6.centos" test_ref="oval:org.mitre.oval:tst:113305"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24060" version="4" class="patch">
      <metadata>
        <title>RHSA-2014:0321: net-snmp security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>net-snmp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0321-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0321.html"/>
        <reference source="CESA" ref_id="CESA-2014:0321"/>
        <reference source="CVE" ref_id="CVE-2014-2284" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2284.html"/>
        <description>The Linux implementation of the ICMP-MIB in Net-SNMP 5.5 before 5.5.2.1, 5.6.x before 5.6.2.1, and 5.7.x before 5.7.2.1 does not properly validate input, which allows remote attackers to cause a denial of service via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-02T11:44:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-03T10:28:25.473-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:35.889-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:31.577-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="net-snmp-perl is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113165"/>
          <criterion comment="net-snmp-python is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:112417"/>
          <criterion comment="net-snmp-devel is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113264"/>
          <criterion comment="net-snmp-utils is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113178"/>
          <criterion comment="net-snmp-libs is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113136"/>
          <criterion comment="net-snmp is earlier than 1:5.5-49.el6_5.1" test_ref="oval:org.mitre.oval:tst:113282"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24049" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0626: openssl097a and openssl098e security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0626-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0626.html"/>
        <reference source="CESA" ref_id="CESA-2014:0626"/>
        <reference source="CVE" ref_id="CVE-2014-0224" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0224.html"/>
        <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a
full-strength, general purpose cryptography library.

It was found that OpenSSL clients and servers could be forced, via a
specially crafted handshake packet, to use weak keying material for
communication. A man-in-the-middle attacker could use this flaw to decrypt
and modify traffic between a client and a server. (CVE-2014-0224)

Note: In order to exploit this flaw, both the server and the client must be
using a vulnerable version of OpenSSL; the server must be using OpenSSL
version 1.0.1 and above, and the client must be using any version of
OpenSSL. For more information about this flaw, refer to:
https://access.redhat.com/site/articles/904433

Red Hat would like to thank the OpenSSL project for reporting this issue.
Upstream acknowledges KIKUCHI Masashi of Lepidum as the original reporter
of this issue.

All OpenSSL users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. For the update to take
effect, all services linked to the OpenSSL library (such as httpd and other
SSL-enabled services) must be restarted or the system rebooted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:19.504-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:10:02.201-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:07.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="openssl097a is earlier than 0:0.9.7a-12.el5_10.1" test_ref="oval:org.mitre.oval:tst:114639"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="openssl098e is earlier than 0:0.9.8e-18.el6_5.2" test_ref="oval:org.mitre.oval:tst:114586"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24035" version="23" class="patch">
      <metadata>
        <title>RHSA-2014:0342: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0342-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0342.html"/>
        <reference source="CESA" ref_id="CESA-2014:0342"/>
        <reference source="CVE" ref_id="CVE-2013-6336" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6336.html"/>
        <reference source="CVE" ref_id="CVE-2013-6337" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6337.html"/>
        <reference source="CVE" ref_id="CVE-2013-6338" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6338.html"/>
        <reference source="CVE" ref_id="CVE-2013-6339" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6339.html"/>
        <reference source="CVE" ref_id="CVE-2013-6340" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6340.html"/>
        <reference source="CVE" ref_id="CVE-2013-7112" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-7112.html"/>
        <reference source="CVE" ref_id="CVE-2013-7114" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-7114.html"/>
        <reference source="CVE" ref_id="CVE-2014-2281" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2281.html"/>
        <reference source="CVE" ref_id="CVE-2014-2283" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2283.html"/>
        <reference source="CVE" ref_id="CVE-2014-2299" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2299.html"/>
        <description>Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-04-02T11:44:11">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-03T10:28:26.021-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:35.198-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:30.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="wireshark-gnome is earlier than 0:1.8.10-7.el6_5" test_ref="oval:org.mitre.oval:tst:113051"/>
          <criterion comment="wireshark is earlier than 0:1.8.10-7.el6_5" test_ref="oval:org.mitre.oval:tst:112693"/>
          <criterion comment="wireshark-devel is earlier than 0:1.8.10-7.el6_5" test_ref="oval:org.mitre.oval:tst:113166"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23999" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0293: udisks security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>udisks</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0293-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0293.html"/>
        <reference source="CESA" ref_id="CESA-2014:0293"/>
        <reference source="CVE" ref_id="CVE-2014-0004" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0004.html"/>
        <description>The udisks package provides a daemon, a D-Bus API, and command line
utilities for managing disks and storage devices.

A stack-based buffer overflow flaw was found in the way udisks handled
files with long path names. A malicious, local user could use this flaw to
create a specially crafted directory structure that, when processed by the
udisks daemon, could lead to arbitrary code execution with the privileges
of the udisks daemon (root). (CVE-2014-0004)

This issue was discovered by Florian Weimer of the Red Hat Product
Security Team.

All udisks users are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:31.658-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23999 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:29.618-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:07.968-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23999 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:38.492-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:01:00.343-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="udisks-devel-docs is earlier than 0:1.0.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:113118"/>
          <criterion comment="udisks-devel is earlier than 0:1.0.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:113071"/>
          <criterion comment="udisks is earlier than 0:1.0.1-7.el6_5" test_ref="oval:org.mitre.oval:tst:113173"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23979" version="27" class="patch">
      <metadata>
        <title>RHSA-2014:0316: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0316-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0316.html"/>
        <reference source="CESA" ref_id="CESA-2014:0316"/>
        <reference source="CVE" ref_id="CVE-2014-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1493.html"/>
        <reference source="CVE" ref_id="CVE-2014-1497" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1497.html"/>
        <reference source="CVE" ref_id="CVE-2014-1505" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1505.html"/>
        <reference source="CVE" ref_id="CVE-2014-1508" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1508.html"/>
        <reference source="CVE" ref_id="CVE-2014-1509" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1509.html"/>
        <reference source="CVE" ref_id="CVE-2014-1510" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1510.html"/>
        <reference source="CVE" ref_id="CVE-2014-1511" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1511.html"/>
        <reference source="CVE" ref_id="CVE-2014-1512" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1512.html"/>
        <reference source="CVE" ref_id="CVE-2014-1513" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1513.html"/>
        <reference source="CVE" ref_id="CVE-2014-1514" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1514.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code with the privileges of the user running
Thunderbird. (CVE-2014-1493, CVE-2014-1510, CVE-2014-1511, CVE-2014-1512,
CVE-2014-1513, CVE-2014-1514)

Several information disclosure flaws were found in the way Thunderbird
processed malformed web content. An attacker could use these flaws to gain
access to sensitive information such as cross-domain content or protected
memory addresses or, potentially, cause Thunderbird to crash.
(CVE-2014-1497, CVE-2014-1508, CVE-2014-1505)

A memory corruption flaw was found in the way Thunderbird rendered certain
PDF files. An attacker able to trick a user into installing a malicious
extension could use this flaw to crash Thunderbird or, potentially, execute
arbitrary code with the privileges of the user running Thunderbird.
(CVE-2014-1509)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Benoit Jacob, Olli Pettay, Jan Varga, Jan de Mooij,
Jesse Ruderman, Dan Gohman, Christoph Diehl, Atte Kettunen, Tyson Smith,
Jesse Schwartzentruber, John Thomson, Robert O'Callahan, Mariusz Mlynski,
Jüri Aedla, George Hotz, and the security research firm VUPEN as the
original reporters of these issues.

Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

For technical details regarding these flaws, refer to the Mozilla security
advisories for Thunderbird 24.4.0. You can find a link to the Mozilla
advisories in the References section of this erratum.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 24.4.0, which corrects these issues.
After installing the update, Thunderbird must be restarted for the changes
to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:32.220-04:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23979 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:32:00.818-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:28.888-04:00">INTERIM</status_change>
            <status_change date="2014-06-02T04:00:07.380-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23979 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:38.130-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:59.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:112930"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:112746"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:113786"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.4.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:113625"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23928" version="9" class="patch">
      <metadata>
        <title>RHSA-2014:0289: flash-plugin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0289-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0289.html"/>
        <reference source="CVE" ref_id="CVE-2014-0503" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0503.html"/>
        <reference source="CVE" ref_id="CVE-2014-0504" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0504.html"/>
        <description>Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows attackers to read the clipboard via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-24T12:19:36">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-04-01T10:03:32.590-04:00">DRAFT</status_change>
            <status_change date="2014-04-21T04:00:33.254-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:27.977-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23928 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:39.342-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:35.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.346-1.el5" test_ref="oval:org.mitre.oval:tst:140987"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.346-1.el6" test_ref="oval:org.mitre.oval:tst:112587"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23897" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0596: libtasn1 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtasn1</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0596-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0596.html"/>
        <reference source="CESA" ref_id="CESA-2014:0596"/>
        <reference source="CVE" ref_id="CVE-2014-3467" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3467.html"/>
        <reference source="CVE" ref_id="CVE-2014-3468" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3468.html"/>
        <reference source="CVE" ref_id="CVE-2014-3469" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-3469.html"/>
        <description>The libtasn1 library provides Abstract Syntax Notation One (ASN.1) parsing
and structures management, and Distinguished Encoding Rules (DER) encoding
and decoding functions.

It was discovered that the asn1_get_bit_der() function of the libtasn1
library incorrectly reported the length of ASN.1-encoded data. Specially
crafted ASN.1 input could cause an application using libtasn1 to perform
an out-of-bounds access operation, causing the application to crash or,
possibly, execute arbitrary code. (CVE-2014-3468)

Multiple incorrect buffer boundary check issues were discovered in
libtasn1. Specially crafted ASN.1 input could cause an application using
libtasn1 to crash. (CVE-2014-3467)

Multiple NULL pointer dereference flaws were found in libtasn1's
asn1_read_value() function. Specially crafted ASN.1 input could cause an
application using libtasn1 to crash, if the application used the
aforementioned function in a certain way. (CVE-2014-3469)

Red Hat would like to thank GnuTLS upstream for reporting these issues.

All libtasn1 users are advised to upgrade to these updated packages, which
correct these issues. For the update to take effect, all applications
linked to the libtasn1 library must be restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-06-09T15:16:45">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-06-10T14:50:18.097-04:00">DRAFT</status_change>
            <status_change date="2014-06-30T04:09:58.242-04:00">INTERIM</status_change>
            <status_change date="2014-07-21T04:01:03.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libtasn1 is earlier than 0:2.3-6.el6_5" test_ref="oval:org.mitre.oval:tst:114822"/>
          <criterion comment="libtasn1-tools is earlier than 0:2.3-6.el6_5" test_ref="oval:org.mitre.oval:tst:114830"/>
          <criterion comment="libtasn1-devel is earlier than 0:2.3-6.el6_5" test_ref="oval:org.mitre.oval:tst:114745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23870" version="3" class="patch">
      <metadata>
        <title>RHSA-2014:0486: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0486-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0486.html"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6954" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6954.html"/>
        <reference source="CVE" ref_id="CVE-2014-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0429.html"/>
        <reference source="CVE" ref_id="CVE-2014-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0446.html"/>
        <reference source="CVE" ref_id="CVE-2014-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0448.html"/>
        <reference source="CVE" ref_id="CVE-2014-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0449.html"/>
        <reference source="CVE" ref_id="CVE-2014-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0451.html"/>
        <reference source="CVE" ref_id="CVE-2014-0452" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0452.html"/>
        <reference source="CVE" ref_id="CVE-2014-0453" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0453.html"/>
        <reference source="CVE" ref_id="CVE-2014-0454" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0454.html"/>
        <reference source="CVE" ref_id="CVE-2014-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0455.html"/>
        <reference source="CVE" ref_id="CVE-2014-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0457.html"/>
        <reference source="CVE" ref_id="CVE-2014-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0458.html"/>
        <reference source="CVE" ref_id="CVE-2014-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0459.html"/>
        <reference source="CVE" ref_id="CVE-2014-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0460.html"/>
        <reference source="CVE" ref_id="CVE-2014-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0461.html"/>
        <reference source="CVE" ref_id="CVE-2014-1876" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1876.html"/>
        <reference source="CVE" ref_id="CVE-2014-2398" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2398.html"/>
        <reference source="CVE" ref_id="CVE-2014-2401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2401.html"/>
        <reference source="CVE" ref_id="CVE-2014-2402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2402.html"/>
        <reference source="CVE" ref_id="CVE-2014-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2409.html"/>
        <reference source="CVE" ref_id="CVE-2014-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2412.html"/>
        <reference source="CVE" ref_id="CVE-2014-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2414.html"/>
        <reference source="CVE" ref_id="CVE-2014-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2420.html"/>
        <reference source="CVE" ref_id="CVE-2014-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2421.html"/>
        <reference source="CVE" ref_id="CVE-2014-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2423.html"/>
        <reference source="CVE" ref_id="CVE-2014-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2427.html"/>
        <reference source="CVE" ref_id="CVE-2014-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-2428.html"/>
        <description>IBM Java SE version 7 includes the IBM Java Runtime Environment and the IBM
Java Software Development Kit.

This update fixes several vulnerabilities in the IBM Java Runtime
Environment and the IBM Java Software Development Kit. Detailed
vulnerability descriptions are linked from the IBM Security alerts
page, listed in the References section. (CVE-2014-0457, CVE-2014-2421,
CVE-2014-0429, CVE-2014-0461, CVE-2014-0455, CVE-2014-2428, CVE-2014-0448,
CVE-2014-0454, CVE-2014-0446, CVE-2014-0452, CVE-2014-0451, CVE-2014-2402,
CVE-2014-2423, CVE-2014-2427, CVE-2014-0458, CVE-2014-2414, CVE-2014-2412,
CVE-2014-2409, CVE-2014-0460, CVE-2013-6954, CVE-2013-6629, CVE-2014-2401,
CVE-2014-0449, CVE-2014-0459, CVE-2014-0453, CVE-2014-2398, CVE-2014-1876,
CVE-2014-2420)

All users of java-1.7.0-ibm are advised to upgrade to these updated
packages, containing the IBM Java SE 7 SR7 release. All running instances
of IBM Java must be restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-05-21T16:07:28">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-05-23T10:29:10.975-04:00">DRAFT</status_change>
            <status_change date="2014-06-09T04:00:21.032-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:56.645-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114142"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114099"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114375"/>
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114105"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:114196"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:113910"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114180"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113583"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:113637"/>
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114182"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114034"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:114263"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23469" version="7" class="patch">
      <metadata>
        <title>RHSA-2014:0246: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0246-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0246.html"/>
        <reference source="CESA" ref_id="CESA-2014:0246"/>
        <reference source="CVE" ref_id="CVE-2014-0092" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0092.html"/>
        <description>lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-03-07T13:03:14">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-03-21T13:20:46.619-04:00">DRAFT</status_change>
            <status_change date="2014-04-07T04:05:11.552-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23469 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:36:00.515-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-12T04:00:23.212-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:23469 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:35.079-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:57.940-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gnutls-devel is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:112972"/>
          <criterion comment="gnutls-utils is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:112709"/>
          <criterion comment="gnutls is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:112982"/>
          <criterion comment="gnutls-guile is earlier than 0:2.8.5-13.el6_5" test_ref="oval:org.mitre.oval:tst:112875"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22561" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0175: piranha security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>piranha</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0175-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0175.html"/>
        <reference source="CESA" ref_id="CESA-2014:0175"/>
        <reference source="CVE" ref_id="CVE-2013-6492" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6492.html"/>
        <description>The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:17.404-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:49.792-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:34.632-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22561 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:16.986-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:22.756-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22561 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:33.636-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:57.443-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="piranha is earlier than 0:0.8.6-4.el6_5.2" test_ref="oval:org.mitre.oval:tst:100423"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22560" version="207" class="patch">
      <metadata>
        <title>RHSA-2014:0135: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0135-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0135.html"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5887" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5887.html"/>
        <reference source="CVE" ref_id="CVE-2013-5888" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5888.html"/>
        <reference source="CVE" ref_id="CVE-2013-5889" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5889.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5898" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5898.html"/>
        <reference source="CVE" ref_id="CVE-2013-5899" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5899.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0375" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0375.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0387" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0387.html"/>
        <reference source="CVE" ref_id="CVE-2014-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0403.html"/>
        <reference source="CVE" ref_id="CVE-2014-0410" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0410.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0415.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0417.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0424.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:22.469-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:48.878-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:34.012-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22560 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:15.507-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:21.321-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22560 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:42.924-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:33.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141020"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140766"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140232"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141122"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140996"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141224"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141145"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141029"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100224"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100435"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:99593"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100378"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100491"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100434"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22535" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0127: librsvg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>librsvg2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0127-01" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0127.html"/>
        <reference source="CESA" ref_id="CESA-2014:0127"/>
        <reference source="CVE" ref_id="CVE-2013-1881" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1881.html"/>
        <description>GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:17.078-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:48.205-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:33.050-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22535 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:18.418-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:21.099-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22535 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:35.663-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:57.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="librsvg2-devel is earlier than 0:2.26.0-6.el6_5.3" test_ref="oval:org.mitre.oval:tst:100475"/>
            <criterion comment="librsvg2 is earlier than 0:2.26.0-6.el6_5.3" test_ref="oval:org.mitre.oval:tst:100428"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kmod-kvm is earlier than 0:83-266.el5.centos.1" test_ref="oval:org.mitre.oval:tst:113808"/>
            <criterion comment="libvirt is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:113557"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22534" version="55" class="patch">
      <metadata>
        <title>RHSA-2014:0132: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0132-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0132.html"/>
        <reference source="CESA" ref_id="CESA-2014:0132"/>
        <reference source="CVE" ref_id="CVE-2014-1477" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1477.html"/>
        <reference source="CVE" ref_id="CVE-2014-1479" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1479.html"/>
        <reference source="CVE" ref_id="CVE-2014-1481" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1481.html"/>
        <reference source="CVE" ref_id="CVE-2014-1482" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1482.html"/>
        <reference source="CVE" ref_id="CVE-2014-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1486.html"/>
        <reference source="CVE" ref_id="CVE-2014-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1487.html"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:16.817-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:47.912-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:31.335-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22534 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:14.930-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:20.704-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22534 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:33.437-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:56.902-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:100310"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="firefox is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:100086"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:113809"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:113156"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22531" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0126: openldap security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0126-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0126.html"/>
        <reference source="CESA" ref_id="CESA-2014:0126"/>
        <reference source="CVE" ref_id="CVE-2013-4449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4449.html"/>
        <description>The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:18.289-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:47.828-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:31.223-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22531 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:15.985-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:20.468-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22531 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:33.116-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:56.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openldap-servers is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:100410"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:100420"/>
          <criterion comment="openldap is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:99960"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:100214"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.23-34.el6_5.1" test_ref="oval:org.mitre.oval:tst:100185"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22528" version="21" class="patch">
      <metadata>
        <title>RHSA-2014:0103: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0103-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0103.html"/>
        <reference source="CESA" ref_id="CESA-2014:0103"/>
        <reference source="CVE" ref_id="CVE-2013-6458" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6458.html"/>
        <reference source="CVE" ref_id="CVE-2014-1447" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1447.html"/>
        <description>Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:16.422-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:47.707-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:30.947-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22528 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:17.298-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:20.207-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:100223"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:100489"/>
          <criterion comment="libvirt is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:100281"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:100480"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:100357"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22499" version="25" class="patch">
      <metadata>
        <title>RHSA-2014:0028: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0028-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0028.html"/>
        <reference source="CVE" ref_id="CVE-2014-0491" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0491.html"/>
        <reference source="CVE" ref_id="CVE-2014-0492" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0492.html"/>
        <description>Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK &amp; Compiler before 4.0.0.1390 allow attackers to defeat the ASLR protection mechanism by leveraging an "address leak."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-28T12:16:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-11T14:03:37.224-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:09.459-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:37.294-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22499 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:31:00.517-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:32:52.671-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:19.918-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22499 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:40.376-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:33.192-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.335-1.el5" test_ref="oval:org.mitre.oval:tst:140999"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.335-1.el6" test_ref="oval:org.mitre.oval:tst:100327"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22473" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0151: wget security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>wget</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0151-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0151.html"/>
        <reference source="CESA" ref_id="CESA-2014:0151"/>
        <reference source="CVE" ref_id="CVE-2010-2252" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2252.html"/>
        <description>GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files via a 3xx redirect to a URL with a .wgetrc filename followed by a 3xx redirect to a URL with a crafted filename, and possibly execute arbitrary code as a consequence of writing to a dotfile in a home directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:19.909-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:45.899-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:27.562-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22473 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:16.152-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:19.463-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22473 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:33.798-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:56.247-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="wget is earlier than 0:1.12-1.11.el6_5" test_ref="oval:org.mitre.oval:tst:100195"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22415" version="311" class="patch">
      <metadata>
        <title>RHSA-2014:0030: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0030-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0030.html"/>
        <reference source="CVE" ref_id="CVE-2013-5870" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5870.html"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5887" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5887.html"/>
        <reference source="CVE" ref_id="CVE-2013-5888" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5888.html"/>
        <reference source="CVE" ref_id="CVE-2013-5889" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5889.html"/>
        <reference source="CVE" ref_id="CVE-2013-5893" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5893.html"/>
        <reference source="CVE" ref_id="CVE-2013-5895" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5895.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5898" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5898.html"/>
        <reference source="CVE" ref_id="CVE-2013-5899" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5899.html"/>
        <reference source="CVE" ref_id="CVE-2013-5902" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5902.html"/>
        <reference source="CVE" ref_id="CVE-2013-5904" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5904.html"/>
        <reference source="CVE" ref_id="CVE-2013-5905" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5905.html"/>
        <reference source="CVE" ref_id="CVE-2013-5906" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5906.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0375" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0375.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0382" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0382.html"/>
        <reference source="CVE" ref_id="CVE-2014-0387" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0387.html"/>
        <reference source="CVE" ref_id="CVE-2014-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0403.html"/>
        <reference source="CVE" ref_id="CVE-2014-0410" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0410.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0415.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0417.html"/>
        <reference source="CVE" ref_id="CVE-2014-0418" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0418.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0424.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-28T12:16:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-11T14:03:37.834-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:07.878-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:35.074-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22415 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:31:00.517-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:32:52.455-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:17.548-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100317"/>
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100240"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:99867"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100244"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100297"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.51-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:99954"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22390" version="8" class="patch">
      <metadata>
        <title>RHSA-2014:0137: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0137-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0137.html"/>
        <reference source="CVE" ref_id="CVE-2014-0497" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0497.html"/>
        <description>Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:22.127-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:43.472-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:23.825-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22390 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:15.851-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:16.940-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22390 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:42.681-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:32.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.336-1.el5" test_ref="oval:org.mitre.oval:tst:141146"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.336-1.el6" test_ref="oval:org.mitre.oval:tst:99514"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22360" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0858: bzip2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>bzip2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0858-03" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0858.html"/>
        <reference source="CVE" ref_id="CVE-2010-0405" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-0405.html"/>
        <description>Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:08.133-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:42.451-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:09.875-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bzip2 is earlier than 0:1.0.5-7.el6_0" test_ref="oval:org.mitre.oval:tst:99905"/>
          <criterion comment="bzip2-libs is earlier than 0:1.0.5-7.el6_0" test_ref="oval:org.mitre.oval:tst:99897"/>
          <criterion comment="bzip2-devel is earlier than 0:1.0.5-7.el6_0" test_ref="oval:org.mitre.oval:tst:99760"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22351" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0950: apr-util security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>apr-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0950-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0950.html"/>
        <reference source="CVE" ref_id="CVE-2010-1623" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1623.html"/>
        <description>Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:00.765-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:40.921-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:08.291-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-util-mysql is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:99823"/>
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:99298"/>
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:99866"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-11.el5_5.2" test_ref="oval:org.mitre.oval:tst:100054"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-util-mysql is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99848"/>
            <criterion comment="apr-util-odbc is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:100112"/>
            <criterion comment="apr-util-devel is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:100092"/>
            <criterion comment="apr-util-ldap is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99963"/>
            <criterion comment="apr-util is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99933"/>
            <criterion comment="apr-util-pgsql is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99237"/>
            <criterion comment="apr-util-sqlite is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:100104"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22343" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0888: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0888-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0888.html"/>
        <reference source="CVE" ref_id="CVE-2010-3864" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3864.html"/>
        <description>Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, when multi-threading and internal caching are enabled on a TLS server, might allow remote attackers to execute arbitrary code via client data that triggers a heap-based buffer overflow, related to (1) the TLS server name extension and (2) elliptic curve cryptography.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:34.994-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:40.242-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:07.465-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl-devel is earlier than 0:1.0.0-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:99699"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:99992"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:99022"/>
          <criterion comment="openssl is earlier than 0:1.0.0-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:99915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22342" version="211" class="patch">
      <metadata>
        <title>RHSA-2010:0873: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0873-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0873.html"/>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1321.html"/>
        <reference source="CVE" ref_id="CVE-2010-3541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3541.html"/>
        <reference source="CVE" ref_id="CVE-2010-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3548.html"/>
        <reference source="CVE" ref_id="CVE-2010-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3549.html"/>
        <reference source="CVE" ref_id="CVE-2010-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3550.html"/>
        <reference source="CVE" ref_id="CVE-2010-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3551.html"/>
        <reference source="CVE" ref_id="CVE-2010-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3556.html"/>
        <reference source="CVE" ref_id="CVE-2010-3559" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3559.html"/>
        <reference source="CVE" ref_id="CVE-2010-3562" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3562.html"/>
        <reference source="CVE" ref_id="CVE-2010-3565" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3565.html"/>
        <reference source="CVE" ref_id="CVE-2010-3566" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3566.html"/>
        <reference source="CVE" ref_id="CVE-2010-3568" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3568.html"/>
        <reference source="CVE" ref_id="CVE-2010-3569" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3569.html"/>
        <reference source="CVE" ref_id="CVE-2010-3572" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3572.html"/>
        <reference source="CVE" ref_id="CVE-2010-3573" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3573.html"/>
        <reference source="CVE" ref_id="CVE-2010-3574" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3574.html"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:24.709-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:40.119-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:07.330-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:99003"/>
          <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:99523"/>
          <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:99871"/>
          <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98977"/>
          <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:99606"/>
          <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:99976"/>
          <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.2-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:99373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22327" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0872: glibc security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0872-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0872.html"/>
        <reference source="CVE" ref_id="CVE-2010-3847" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3847.html"/>
        <reference source="CVE" ref_id="CVE-2010-3856" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3856.html"/>
        <description>ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:09.971-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:39.142-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:05.823-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-devel is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:99543"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:99766"/>
          <criterion comment="glibc is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:99757"/>
          <criterion comment="nscd is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:99369"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:99888"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:99889"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.7.el6_0.3" test_ref="oval:org.mitre.oval:tst:99672"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22323" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0890: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0890-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0890.html"/>
        <reference source="CVE" ref_id="CVE-2010-3711" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3711.html"/>
        <description>libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:46.717-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:38.527-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:05.116-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pidgin-docs is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:99814"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:99574"/>
          <criterion comment="pidgin-perl is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:99890"/>
          <criterion comment="libpurple is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:100010"/>
          <criterion comment="libpurple-perl is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:99581"/>
          <criterion comment="finch-devel is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:99996"/>
          <criterion comment="finch is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:99378"/>
          <criterion comment="libpurple-devel is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:99826"/>
          <criterion comment="pidgin-devel is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:99993"/>
          <criterion comment="pidgin is earlier than 0:2.6.6-6.el6_0" test_ref="oval:org.mitre.oval:tst:99702"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22318" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0859: poppler security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>poppler</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0859-03" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0859.html"/>
        <reference source="CVE" ref_id="CVE-2010-3702" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3702.html"/>
        <reference source="CVE" ref_id="CVE-2010-3703" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3703.html"/>
        <reference source="CVE" ref_id="CVE-2010-3704" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3704.html"/>
        <description>The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with a crafted PostScript Type1 font that contains a negative array index, which bypasses input validation and triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:27.489-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:38.429-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:04.706-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="poppler-qt4 is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99456"/>
          <criterion comment="poppler-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99756"/>
          <criterion comment="poppler-qt-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99650"/>
          <criterion comment="poppler-glib-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99747"/>
          <criterion comment="poppler-qt4-devel is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99651"/>
          <criterion comment="poppler-qt is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99774"/>
          <criterion comment="poppler-glib is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99829"/>
          <criterion comment="poppler-utils is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99904"/>
          <criterion comment="poppler is earlier than 0:0.12.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99870"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22313" version="302" class="patch">
      <metadata>
        <title>RHSA-2010:0987: java-1.6.0-ibm security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0987-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0987.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1321.html"/>
        <reference source="CVE" ref_id="CVE-2010-3541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3541.html"/>
        <reference source="CVE" ref_id="CVE-2010-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3548.html"/>
        <reference source="CVE" ref_id="CVE-2010-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3549.html"/>
        <reference source="CVE" ref_id="CVE-2010-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3550.html"/>
        <reference source="CVE" ref_id="CVE-2010-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3551.html"/>
        <reference source="CVE" ref_id="CVE-2010-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3553.html"/>
        <reference source="CVE" ref_id="CVE-2010-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3556.html"/>
        <reference source="CVE" ref_id="CVE-2010-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3557.html"/>
        <reference source="CVE" ref_id="CVE-2010-3558" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3558.html"/>
        <reference source="CVE" ref_id="CVE-2010-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3560.html"/>
        <reference source="CVE" ref_id="CVE-2010-3562" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3562.html"/>
        <reference source="CVE" ref_id="CVE-2010-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3563.html"/>
        <reference source="CVE" ref_id="CVE-2010-3565" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3565.html"/>
        <reference source="CVE" ref_id="CVE-2010-3566" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3566.html"/>
        <reference source="CVE" ref_id="CVE-2010-3568" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3568.html"/>
        <reference source="CVE" ref_id="CVE-2010-3569" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3569.html"/>
        <reference source="CVE" ref_id="CVE-2010-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3571.html"/>
        <reference source="CVE" ref_id="CVE-2010-3572" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3572.html"/>
        <reference source="CVE" ref_id="CVE-2010-3573" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3573.html"/>
        <reference source="CVE" ref_id="CVE-2010-3574" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3574.html"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:38.612-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:37.857-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:04.398-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:100028"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99711"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99988"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99645"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:99841"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:100039"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:100029"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.3.el5" test_ref="oval:org.mitre.oval:tst:100048"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99840"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:100131"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99487"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99638"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99977"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99913"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el6" test_ref="oval:org.mitre.oval:tst:99549"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22295" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0969: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0969-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0969.html"/>
        <reference source="CVE" ref_id="CVE-2010-3768" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3768.html"/>
        <reference source="CVE" ref_id="CVE-2010-3776" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3776.html"/>
        <reference source="CVE" ref_id="CVE-2010-3777" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3777.html"/>
        <description>Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:17.581-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:37.191-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:03.563-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.7-3.el6_0" test_ref="oval:org.mitre.oval:tst:100110"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22292" version="207" class="patch">
      <metadata>
        <title>RHSA-2014:0134: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0134-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0134.html"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5887" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5887.html"/>
        <reference source="CVE" ref_id="CVE-2013-5888" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5888.html"/>
        <reference source="CVE" ref_id="CVE-2013-5889" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5889.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5898" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5898.html"/>
        <reference source="CVE" ref_id="CVE-2013-5899" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5899.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0375" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0375.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0387" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0387.html"/>
        <reference source="CVE" ref_id="CVE-2014-0403" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0403.html"/>
        <reference source="CVE" ref_id="CVE-2014-0410" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0410.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0415.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0417.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0424.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:18.764-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:41.561-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:20.929-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22292 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:16.349-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:15.660-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22292 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:42.353-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:31.690-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140896"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140881"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141052"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141081"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141036"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141057"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100082"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100483"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:99949"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100370"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100425"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100295"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22287" version="39" class="patch">
      <metadata>
        <title>RHSA-2014:0159: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0159-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0159.html"/>
        <reference source="CESA" ref_id="CESA-2014:0159"/>
        <reference source="CVE" ref_id="CVE-2013-2929" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2929.html"/>
        <reference source="CVE" ref_id="CVE-2013-6381" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6381.html"/>
        <reference source="CVE" ref_id="CVE-2013-7263" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-7263.html"/>
        <reference source="CVE" ref_id="CVE-2013-7265" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-7265.html"/>
        <description>The pn_recvmsg function in net/phonet/datagram.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:19.674-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:41.386-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:20.739-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22287 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:17.535-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:15.101-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22287 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:40.266-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:54.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:100383"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:99779"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:99656"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:100084"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:100473"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:100076"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:100521"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:100307"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:100482"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:99943"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:100510"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:100263"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.5.1.el6" test_ref="oval:org.mitre.oval:tst:100286"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22286" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0999: libvpx security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libvpx</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0999-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0999.html"/>
        <reference source="CVE" ref_id="CVE-2010-4203" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4203.html"/>
        <description>WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via invalid frames.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:05.002-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:36.769-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:03.161-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvpx-utils is earlier than 0:0.9.0-8.el6_0" test_ref="oval:org.mitre.oval:tst:100157"/>
          <criterion comment="libvpx is earlier than 0:0.9.0-8.el6_0" test_ref="oval:org.mitre.oval:tst:100138"/>
          <criterion comment="libvpx-devel is earlier than 0:0.9.0-8.el6_0" test_ref="oval:org.mitre.oval:tst:100071"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22285" version="224" class="patch">
      <metadata>
        <title>RHSA-2010:0865: java-1.6.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0865-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0865.html"/>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html"/>
        <reference source="CVE" ref_id="CVE-2010-3541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3541.html"/>
        <reference source="CVE" ref_id="CVE-2010-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3548.html"/>
        <reference source="CVE" ref_id="CVE-2010-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3549.html"/>
        <reference source="CVE" ref_id="CVE-2010-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3551.html"/>
        <reference source="CVE" ref_id="CVE-2010-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3553.html"/>
        <reference source="CVE" ref_id="CVE-2010-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3554.html"/>
        <reference source="CVE" ref_id="CVE-2010-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3557.html"/>
        <reference source="CVE" ref_id="CVE-2010-3561" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3561.html"/>
        <reference source="CVE" ref_id="CVE-2010-3562" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3562.html"/>
        <reference source="CVE" ref_id="CVE-2010-3564" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3564.html"/>
        <reference source="CVE" ref_id="CVE-2010-3565" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3565.html"/>
        <reference source="CVE" ref_id="CVE-2010-3567" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3567.html"/>
        <reference source="CVE" ref_id="CVE-2010-3568" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3568.html"/>
        <reference source="CVE" ref_id="CVE-2010-3569" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3569.html"/>
        <reference source="CVE" ref_id="CVE-2010-3573" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3573.html"/>
        <reference source="CVE" ref_id="CVE-2010-3574" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3574.html"/>
        <description>Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable downstream vendor that HttpURLConnection does not properly check for the allowHttpTrace permission, which allows untrusted code to perform HTTP TRACE requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:24.724-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:36.268-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:02.725-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.31.b17.el6_0" test_ref="oval:org.mitre.oval:tst:99418"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.31.b17.el6_0" test_ref="oval:org.mitre.oval:tst:99882"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.31.b17.el6_0" test_ref="oval:org.mitre.oval:tst:99909"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.31.b17.el6_0" test_ref="oval:org.mitre.oval:tst:99547"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.31.b17.el6_0" test_ref="oval:org.mitre.oval:tst:99536"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22278" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0889: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0889-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0889.html"/>
        <reference source="CESA" ref_id="CESA-2010:0889"/>
        <reference source="CVE" ref_id="CVE-2010-3855" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3855.html"/>
        <description>Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TrueType GX font.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:27.810-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:36.039-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:02.492-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:99759"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:99767"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_5.1" test_ref="oval:org.mitre.oval:tst:100020"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:99899"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:99736"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_0.2" test_ref="oval:org.mitre.oval:tst:99941"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22276" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0860: samba security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0860-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0860.html"/>
        <reference source="CVE" ref_id="CVE-2010-3069" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3069.html"/>
        <description>Stack-based buffer overflow in the (1) sid_parse and (2) dom_sid_parse functions in Samba before 3.5.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Windows Security ID (SID) on a file share.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:20.039-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:35.600-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:02.025-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="samba-client is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99834"/>
          <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99815"/>
          <criterion comment="samba is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99545"/>
          <criterion comment="samba-doc is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99602"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99746"/>
          <criterion comment="samba-common is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99808"/>
          <criterion comment="samba-winbind is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99431"/>
          <criterion comment="samba-winbind-clients is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99282"/>
          <criterion comment="samba-winbind-devel is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99856"/>
          <criterion comment="libsmbclient is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99659"/>
          <criterion comment="samba-swat is earlier than 0:3.5.4-68.el6_0.1" test_ref="oval:org.mitre.oval:tst:99886"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22273" version="120" class="patch">
      <metadata>
        <title>RHSA-2010:0861: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0861-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0861.html"/>
        <reference source="CVE" ref_id="CVE-2010-3175" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3175.html"/>
        <reference source="CVE" ref_id="CVE-2010-3176" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3176.html"/>
        <reference source="CVE" ref_id="CVE-2010-3177" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3177.html"/>
        <reference source="CVE" ref_id="CVE-2010-3178" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3178.html"/>
        <reference source="CVE" ref_id="CVE-2010-3179" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3179.html"/>
        <reference source="CVE" ref_id="CVE-2010-3180" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3180.html"/>
        <reference source="CVE" ref_id="CVE-2010-3182" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3182.html"/>
        <reference source="CVE" ref_id="CVE-2010-3183" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3183.html"/>
        <reference source="CVE" ref_id="CVE-2010-3765" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3765.html"/>
        <description>Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:08.551-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:35.296-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:01.736-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xulrunner-devel is earlier than 0:1.9.2.12-1.el6_0" test_ref="oval:org.mitre.oval:tst:99511"/>
          <criterion comment="xulrunner is earlier than 0:1.9.2.12-1.el6_0" test_ref="oval:org.mitre.oval:tst:99488"/>
          <criterion comment="firefox is earlier than 0:3.6.12-1.el6_0" test_ref="oval:org.mitre.oval:tst:99900"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22269" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0863: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0863-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0863.html"/>
        <reference source="CVE" ref_id="CVE-2010-1322" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1322.html"/>
        <description>The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of service (daemon crash), or possibly obtain sensitive information, spoof authorization, or execute arbitrary code, via a TGS request that triggers an uninitialized pointer dereference, as demonstrated by a request from a Windows Active Directory client.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:00.294-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:35.089-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:01.407-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99275"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99039"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99496"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99560"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99806"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99752"/>
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:99807"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22268" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0934: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0934-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0934.html"/>
        <reference source="CVE" ref_id="CVE-2010-3654" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3654.html"/>
        <reference source="CVE" ref_id="CVE-2010-4091" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4091.html"/>
        <description>The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers memory corruption, involving the printSeps function. NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:25.581-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:34.977-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:03:01.277-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.1-1.el5" test_ref="oval:org.mitre.oval:tst:99895"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.1-1.el5" test_ref="oval:org.mitre.oval:tst:99982"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.1-1.el6" test_ref="oval:org.mitre.oval:tst:99687"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.1-1.el6" test_ref="oval:org.mitre.oval:tst:100085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22238" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0864: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0864-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0864.html"/>
        <reference source="CVE" ref_id="CVE-2010-2805" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2805.html"/>
        <reference source="CVE" ref_id="CVE-2010-2806" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2806.html"/>
        <reference source="CVE" ref_id="CVE-2010-2808" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2808.html"/>
        <reference source="CVE" ref_id="CVE-2010-3311" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3311.html"/>
        <description>Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:19.636-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:32.486-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:59.246-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:98946"/>
          <criterion comment="freetype is earlier than 0:2.3.11-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:99842"/>
          <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:99869"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22234" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0975: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0975-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0975.html"/>
        <reference source="CVE" ref_id="CVE-2010-3613" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3613.html"/>
        <reference source="CVE" ref_id="CVE-2010-3614" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3614.html"/>
        <description>named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:20.677-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:32.354-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:59.079-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99995"/>
          <criterion comment="bind-chroot is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99625"/>
          <criterion comment="bind-sdb is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99999"/>
          <criterion comment="bind-libs is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99538"/>
          <criterion comment="bind-devel is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99925"/>
          <criterion comment="bind-utils is earlier than 32:9.7.0-5.P2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99584"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22223" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:1003: git security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>git</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:1003-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-1003.html"/>
        <reference source="CVE" ref_id="CVE-2010-3906" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3906.html"/>
        <description>Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:07.232-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:32.051-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:58.190-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="git-cvs is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:100070"/>
          <criterion comment="emacs-git-el is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:100087"/>
          <criterion comment="git-email is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99768"/>
          <criterion comment="gitk is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99883"/>
          <criterion comment="git-daemon is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99181"/>
          <criterion comment="git-svn is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99724"/>
          <criterion comment="git-all is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99843"/>
          <criterion comment="git-gui is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:100068"/>
          <criterion comment="emacs-git is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99946"/>
          <criterion comment="gitweb is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:99938"/>
          <criterion comment="git is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:100161"/>
          <criterion comment="perl-Git is earlier than 0:1.7.1-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:100053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22210" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0866: cups security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0866-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0866.html"/>
        <reference source="CVE" ref_id="CVE-2010-2941" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2941.html"/>
        <description>ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:04.188-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:31.285-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:56.780-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="cups-php is earlier than 1:1.4.2-35.el6_0.1" test_ref="oval:org.mitre.oval:tst:99505"/>
          <criterion comment="cups-lpd is earlier than 1:1.4.2-35.el6_0.1" test_ref="oval:org.mitre.oval:tst:99819"/>
          <criterion comment="cups-devel is earlier than 1:1.4.2-35.el6_0.1" test_ref="oval:org.mitre.oval:tst:99907"/>
          <criterion comment="cups is earlier than 1:1.4.2-35.el6_0.1" test_ref="oval:org.mitre.oval:tst:99816"/>
          <criterion comment="cups-libs is earlier than 1:1.4.2-35.el6_0.1" test_ref="oval:org.mitre.oval:tst:99684"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22203" version="111" class="patch">
      <metadata>
        <title>RHSA-2014:0139: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0139-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0139.html"/>
        <reference source="CESA" ref_id="CESA-2014:0139"/>
        <reference source="CVE" ref_id="CVE-2012-6152" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6152.html"/>
        <reference source="CVE" ref_id="CVE-2013-6477" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6477.html"/>
        <reference source="CVE" ref_id="CVE-2013-6478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6478.html"/>
        <reference source="CVE" ref_id="CVE-2013-6479" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6479.html"/>
        <reference source="CVE" ref_id="CVE-2013-6481" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6481.html"/>
        <reference source="CVE" ref_id="CVE-2013-6482" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6482.html"/>
        <reference source="CVE" ref_id="CVE-2013-6483" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6483.html"/>
        <reference source="CVE" ref_id="CVE-2013-6484" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6484.html"/>
        <reference source="CVE" ref_id="CVE-2013-6485" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6485.html"/>
        <reference source="CVE" ref_id="CVE-2013-6487" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6487.html"/>
        <reference source="CVE" ref_id="CVE-2013-6489" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6489.html"/>
        <reference source="CVE" ref_id="CVE-2013-6490" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6490.html"/>
        <reference source="CVE" ref_id="CVE-2014-0020" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0020.html"/>
        <description>The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:15.312-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:39.038-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:18.086-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22203 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:17.941-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:13.664-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22203 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:34.799-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:53.359-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpurple is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100193"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100391"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100046"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100258"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:99785"/>
            <criterion comment="finch is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100061"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:100448"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:99911"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-32.el5" test_ref="oval:org.mitre.oval:tst:99966"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpurple is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100119"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100321"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100252"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100189"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100505"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100413"/>
            <criterion comment="finch is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100426"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100512"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100487"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-27.el6" test_ref="oval:org.mitre.oval:tst:100181"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22195" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1268: firefox security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1268-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1268.html"/>
        <reference source="CESA" ref_id="CESA-2011:1268"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

The RHSA-2011:1242 Firefox update rendered HTTPS certificates signed by a
certain Certificate Authority (CA) as untrusted, but made an exception for
a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.6.22. After installing the update, Firefox must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:10.882-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:30.237-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:54.511-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22195 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:40.192-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:46.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el5_7" test_ref="oval:org.mitre.oval:tst:98144"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.22-1.el5_7" test_ref="oval:org.mitre.oval:tst:98450"/>
            <criterion comment="firefox is earlier than 0:3.6.22-1.el5_7" test_ref="oval:org.mitre.oval:tst:98348"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el6_1" test_ref="oval:org.mitre.oval:tst:98413"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.22-1.el6_1" test_ref="oval:org.mitre.oval:tst:98050"/>
            <criterion comment="firefox is earlier than 0:3.6.22-1.el6_1" test_ref="oval:org.mitre.oval:tst:98522"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22193" version="68" class="patch">
      <metadata>
        <title>RHSA-2011:1341: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1341-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1341.html"/>
        <reference source="CESA" ref_id="CESA-2011:1341"/>
        <reference source="CVE" ref_id="CVE-2011-2372" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2372.html"/>
        <reference source="CVE" ref_id="CVE-2011-2995" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2995.html"/>
        <reference source="CVE" ref_id="CVE-2011-2998" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2998.html"/>
        <reference source="CVE" ref_id="CVE-2011-2999" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2999.html"/>
        <reference source="CVE" ref_id="CVE-2011-3000" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3000.html"/>
        <description>Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:50.422-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:30.009-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:54.145-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el5_7" test_ref="oval:org.mitre.oval:tst:98580"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.23-1.el5_7" test_ref="oval:org.mitre.oval:tst:98437"/>
            <criterion comment="firefox is earlier than 0:3.6.23-2.el5_7" test_ref="oval:org.mitre.oval:tst:98592"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:3.6.23-2.el6_1" test_ref="oval:org.mitre.oval:tst:98221"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98338"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.23-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98441"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22189" version="122" class="patch">
      <metadata>
        <title>RHSA-2014:0097: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0097-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0097.html"/>
        <reference source="CESA" ref_id="CESA-2014:0097"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-28T12:16:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-11T14:03:36.709-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:04.033-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:33.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22189 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:31:00.517-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:32:53.300-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:12.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:100218"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:100267"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:99398"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:100331"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el5_10" test_ref="oval:org.mitre.oval:tst:100042"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:99953"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:100233"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:99903"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:100373"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el6_5" test_ref="oval:org.mitre.oval:tst:99792"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22188" version="68" class="patch">
      <metadata>
        <title>RHSA-2010:0891: pam security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>pam</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0891-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0891.html"/>
        <reference source="CVE" ref_id="CVE-2010-3316" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3316.html"/>
        <reference source="CVE" ref_id="CVE-2010-3435" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3435.html"/>
        <reference source="CVE" ref_id="CVE-2010-3853" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3853.html"/>
        <reference source="CVE" ref_id="CVE-2010-4707" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4707.html"/>
        <reference source="CVE" ref_id="CVE-2010-4708" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4708.html"/>
        <description>The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow local users to run programs with an unintended environment by executing a program that relies on the pam_env PAM check.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:58.155-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:29.805-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:53.625-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pam-devel is earlier than 0:1.1.1-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:99964"/>
          <criterion comment="pam is earlier than 0:1.1.1-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:99967"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22167" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1790: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1790-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1790.html"/>
        <reference source="CESA" ref_id="CESA-2011:1790"/>
        <reference source="CVE" ref_id="CVE-2011-1530" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1530.html"/>
        <description>The process_tgs_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.9 through 1.9.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS request that triggers an error other than the KRB5_KDB_NOENTRY error.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:56.818-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:28.563-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:52.052-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-devel is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:98886"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:98629"/>
          <criterion comment="krb5-workstation is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:98783"/>
          <criterion comment="krb5-libs is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:98784"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:98669"/>
          <criterion comment="krb5-server is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:98360"/>
          <criterion comment="krb5 is earlier than 0:1.9-22.el6_2.1" test_ref="oval:org.mitre.oval:tst:98208"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22166" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1814: ipmitool security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ipmitool</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1814-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1814.html"/>
        <reference source="CESA" ref_id="CESA-2011:1814"/>
        <reference source="CVE" ref_id="CVE-2011-4339" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4339.html"/>
        <description>ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to kill arbitrary processes by writing to this file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:03.274-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:28.476-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:51.909-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="ipmitool is earlier than 0:1.8.11-12.el6_2.1" test_ref="oval:org.mitre.oval:tst:98826"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22163" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0918: cvs security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>cvs</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0918-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0918.html"/>
        <reference source="CVE" ref_id="CVE-2010-3846" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3846.html"/>
        <description>Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:03.595-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:28.225-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:51.609-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="cvs is earlier than 0:1.11.23-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:99932"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22153" version="94" class="patch">
      <metadata>
        <title>RHSA-2011:1780: tomcat6 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1780-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1780.html"/>
        <reference source="CESA" ref_id="CESA-2011:1780"/>
        <reference source="CVE" ref_id="CVE-2011-1184" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1184.html"/>
        <reference source="CVE" ref_id="CVE-2011-2204" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2204.html"/>
        <reference source="CVE" ref_id="CVE-2011-2526" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2526.html"/>
        <reference source="CVE" ref_id="CVE-2011-3190" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3190.html"/>
        <reference source="CVE" ref_id="CVE-2011-5062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5062.html"/>
        <reference source="CVE" ref_id="CVE-2011-5063" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5063.html"/>
        <reference source="CVE" ref_id="CVE-2011-5064" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5064.html"/>
        <description>DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a different vulnerability than CVE-2011-1184.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:45.742-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:27.708-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:50.895-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:98519"/>
            <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:98838"/>
            <criterion comment="tomcat6-lib is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:98884"/>
            <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:98617"/>
            <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:98853"/>
            <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:98854"/>
            <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:98590"/>
            <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:98568"/>
            <criterion comment="tomcat6 is earlier than 0:6.0.24-35.el6_1" test_ref="oval:org.mitre.oval:tst:98423"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-35.el6" test_ref="oval:org.mitre.oval:tst:98194"/>
            <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-35.el6" test_ref="oval:org.mitre.oval:tst:99048"/>
            <criterion comment="tomcat6-lib is earlier than 0:6.0.24-35.el6" test_ref="oval:org.mitre.oval:tst:99014"/>
            <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-35.el6" test_ref="oval:org.mitre.oval:tst:99054"/>
            <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-35.el6" test_ref="oval:org.mitre.oval:tst:98941"/>
            <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-35.el6" test_ref="oval:org.mitre.oval:tst:98289"/>
            <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-35.el6" test_ref="oval:org.mitre.oval:tst:99016"/>
            <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-35.el6" test_ref="oval:org.mitre.oval:tst:98608"/>
            <criterion comment="tomcat6 is earlier than 0:6.0.24-35.el6" test_ref="oval:org.mitre.oval:tst:98734"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22139" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1507: libarchive security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libarchive</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1507-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1507.html"/>
        <reference source="CVE" ref_id="CVE-2011-1777" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1777.html"/>
        <reference source="CVE" ref_id="CVE-2011-1778" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1778.html"/>
        <description>Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:06.060-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:25.009-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:48.393-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libarchive-devel is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:98860"/>
          <criterion comment="libarchive is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:98300"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22138" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1815: icu security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>icu</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1815-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1815.html"/>
        <reference source="CESA" ref_id="CESA-2011:1815"/>
        <reference source="CVE" ref_id="CVE-2011-4599" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4599.html"/>
        <description>Stack-based buffer overflow in the _canonicalize function in common/uloc.c in International Components for Unicode (ICU) before 49.1 allows remote attackers to execute arbitrary code via a crafted locale ID that is not properly handled during variant canonicalization.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:44.756-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:24.885-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:48.261-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libicu-devel is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:98771"/>
            <criterion comment="libicu-doc is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:98751"/>
            <criterion comment="libicu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:98898"/>
            <criterion comment="icu is earlier than 0:4.2.1-9.1.el6_2" test_ref="oval:org.mitre.oval:tst:98424"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libicu-devel is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:98896"/>
            <criterion comment="libicu-doc is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:98133"/>
            <criterion comment="libicu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:98443"/>
            <criterion comment="icu is earlier than 0:3.6-5.16.1" test_ref="oval:org.mitre.oval:tst:98768"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22133" version="549" class="patch">
      <metadata>
        <title>RHSA-2011:1434: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1434-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1434.html"/>
        <reference source="CVE" ref_id="CVE-2011-2094" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2094.html"/>
        <reference source="CVE" ref_id="CVE-2011-2095" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2095.html"/>
        <reference source="CVE" ref_id="CVE-2011-2096" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2096.html"/>
        <reference source="CVE" ref_id="CVE-2011-2097" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2097.html"/>
        <reference source="CVE" ref_id="CVE-2011-2098" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2098.html"/>
        <reference source="CVE" ref_id="CVE-2011-2099" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2099.html"/>
        <reference source="CVE" ref_id="CVE-2011-2101" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2101.html"/>
        <reference source="CVE" ref_id="CVE-2011-2104" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2104.html"/>
        <reference source="CVE" ref_id="CVE-2011-2105" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2105.html"/>
        <reference source="CVE" ref_id="CVE-2011-2107" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2107.html"/>
        <reference source="CVE" ref_id="CVE-2011-2130" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2130.html"/>
        <reference source="CVE" ref_id="CVE-2011-2134" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2134.html"/>
        <reference source="CVE" ref_id="CVE-2011-2135" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2135.html"/>
        <reference source="CVE" ref_id="CVE-2011-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2136.html"/>
        <reference source="CVE" ref_id="CVE-2011-2137" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2137.html"/>
        <reference source="CVE" ref_id="CVE-2011-2138" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2138.html"/>
        <reference source="CVE" ref_id="CVE-2011-2139" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2139.html"/>
        <reference source="CVE" ref_id="CVE-2011-2140" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2140.html"/>
        <reference source="CVE" ref_id="CVE-2011-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2414.html"/>
        <reference source="CVE" ref_id="CVE-2011-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2415.html"/>
        <reference source="CVE" ref_id="CVE-2011-2416" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2416.html"/>
        <reference source="CVE" ref_id="CVE-2011-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2417.html"/>
        <reference source="CVE" ref_id="CVE-2011-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2424.html"/>
        <reference source="CVE" ref_id="CVE-2011-2425" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2425.html"/>
        <reference source="CVE" ref_id="CVE-2011-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2426.html"/>
        <reference source="CVE" ref_id="CVE-2011-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2427.html"/>
        <reference source="CVE" ref_id="CVE-2011-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2428.html"/>
        <reference source="CVE" ref_id="CVE-2011-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2429.html"/>
        <reference source="CVE" ref_id="CVE-2011-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2430.html"/>
        <reference source="CVE" ref_id="CVE-2011-2431" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2431.html"/>
        <reference source="CVE" ref_id="CVE-2011-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2432.html"/>
        <reference source="CVE" ref_id="CVE-2011-2433" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2433.html"/>
        <reference source="CVE" ref_id="CVE-2011-2434" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2434.html"/>
        <reference source="CVE" ref_id="CVE-2011-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2435.html"/>
        <reference source="CVE" ref_id="CVE-2011-2436" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2436.html"/>
        <reference source="CVE" ref_id="CVE-2011-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2437.html"/>
        <reference source="CVE" ref_id="CVE-2011-2438" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2438.html"/>
        <reference source="CVE" ref_id="CVE-2011-2439" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2439.html"/>
        <reference source="CVE" ref_id="CVE-2011-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2440.html"/>
        <reference source="CVE" ref_id="CVE-2011-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2442.html"/>
        <reference source="CVE" ref_id="CVE-2011-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2444.html"/>
        <reference source="CVE" ref_id="CVE-2011-4374" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4374.html"/>
        <description>Integer overflow in Adobe Reader 9.x before 9.4.6 on Linux allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:05.688-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:23.624-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:46.895-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.6-1.el5" test_ref="oval:org.mitre.oval:tst:97774"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.6-1.el5" test_ref="oval:org.mitre.oval:tst:98628"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.6-1.el6" test_ref="oval:org.mitre.oval:tst:98469"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.6-1.el6" test_ref="oval:org.mitre.oval:tst:98773"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22129" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1328: qt security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1328-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1328.html"/>
        <reference source="CVE" ref_id="CVE-2011-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3193.html"/>
        <reference source="CVE" ref_id="CVE-2011-3194" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3194.html"/>
        <description>Buffer overflow in the TIFF reader in gui/image/qtiffhandler.cpp in Qt 4.7.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the TIFFTAG_SAMPLESPERPIXEL tag in a greyscale TIFF image with multiple samples per pixel.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:15.379-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:23.321-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:46.466-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qt-odbc is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:98379"/>
          <criterion comment="qt-demos is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:98107"/>
          <criterion comment="qt-mysql is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:98183"/>
          <criterion comment="qt-x11 is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:97613"/>
          <criterion comment="qt-doc is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:98285"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:98460"/>
          <criterion comment="qt-postgresql is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:98435"/>
          <criterion comment="qt-sqlite is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:98266"/>
          <criterion comment="qt is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:98486"/>
          <criterion comment="qt-examples is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:98254"/>
          <criterion comment="qt-devel is earlier than 1:4.6.2-20.el6" test_ref="oval:org.mitre.oval:tst:98521"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22128" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:1166: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1166-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1166.html"/>
        <reference source="CVE" ref_id="CVE-2011-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0084.html"/>
        <reference source="CVE" ref_id="CVE-2011-2378" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2378.html"/>
        <reference source="CVE" ref_id="CVE-2011-2982" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2982.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, SeaMonkey 1.x and 2.x, and possibly other products allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:23.030-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:23.206-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:46.322-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.12-1.el6_1" test_ref="oval:org.mitre.oval:tst:98006"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22125" version="94" class="patch">
      <metadata>
        <title>RHSA-2011:1087: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1087-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1087.html"/>
        <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html"/>
        <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html"/>
        <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html"/>
        <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html"/>
        <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html"/>
        <reference source="CVE" ref_id="CVE-2011-0873" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0873.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:18.042-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:22.970-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:45.991-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97848"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97344"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98141"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98281"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98115"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97695"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97844"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98207"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98174"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97523"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98329"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98335"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98113"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97576"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98158"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22117" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1441: icedtea-web security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1441-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1441.html"/>
        <reference source="CVE" ref_id="CVE-2011-3377" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3377.html"/>
        <description>The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:35.739-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.879-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:44.574-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.0.6-1.el6_1" test_ref="oval:org.mitre.oval:tst:98620"/>
          <criterion comment="icedtea-web is earlier than 0:1.0.6-1.el6_1" test_ref="oval:org.mitre.oval:tst:98659"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22116" version="94" class="patch">
      <metadata>
        <title>RHSA-2011:1478: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1478-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1478.html"/>
        <reference source="CVE" ref_id="CVE-2011-3545" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3545.html"/>
        <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html"/>
        <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html"/>
        <reference source="CVE" ref_id="CVE-2011-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3549.html"/>
        <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html"/>
        <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html"/>
        <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, 1.4.2_33 and earlier, and JRockit R28.1.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to RMI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:37.349-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.630-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:44.297-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98297"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98754"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98475"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98775"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98729"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97885"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98668"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98657"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98763"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98345"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97910"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98861"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98667"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98598"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98324"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22113" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1458: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1458-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1458.html"/>
        <reference source="CESA" ref_id="CESA-2011:1458"/>
        <reference source="CVE" ref_id="CVE-2011-4313" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4313.html"/>
        <description>query.c in ISC BIND 9.0.x through 9.6.x, 9.4-ESV through 9.4-ESV-R5, 9.6-ESV through 9.6-ESV-R5, 9.7.0 through 9.7.4, 9.8.0 through 9.8.1, and 9.9.0a1 through 9.9.0b1 allows remote attackers to cause a denial of service (assertion failure and named exit) via unknown vectors related to recursive DNS queries, error logging, and the caching of an invalid record by the resolver.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:16.451-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.410-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:44.035-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98079"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98197"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98439"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98132"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98609"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98408"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98665"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" test_ref="oval:org.mitre.oval:tst:98532"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98698"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98367"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98426"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98202"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98553"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.3" test_ref="oval:org.mitre.oval:tst:98690"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22109" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1242: firefox security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1242-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1242.html"/>
        <reference source="CESA" ref_id="CESA-2011:1242"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Firefox; however, affected certificates issued
after this date cannot be re-enabled or used. (BZ#734316)

All Firefox users should upgrade to these updated packages, which contain
a backported patch. After installing the update, Firefox must be restarted
for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:19.848-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.256-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:43.845-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22109 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:38.859-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:46.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el5_7" test_ref="oval:org.mitre.oval:tst:98420"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-3.el5_7" test_ref="oval:org.mitre.oval:tst:97841"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el6_1" test_ref="oval:org.mitre.oval:tst:98240"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-3.el6_1" test_ref="oval:org.mitre.oval:tst:98391"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22108" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1852: krb5-appl security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>krb5-appl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1852-02" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1852.html"/>
        <reference source="CESA" ref_id="CESA-2011:1852"/>
        <reference source="CVE" ref_id="CVE-2011-4862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4862.html"/>
        <description>Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:28.684-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:21.168-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:43.738-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-appl-clients is earlier than 0:1.0.1-7.el6_2" test_ref="oval:org.mitre.oval:tst:98908"/>
          <criterion comment="krb5-appl-servers is earlier than 0:1.0.1-7.el6_2" test_ref="oval:org.mitre.oval:tst:98952"/>
          <criterion comment="krb5-appl is earlier than 0:1.0.1-7.el6_2" test_ref="oval:org.mitre.oval:tst:98864"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22105" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:1002: mod_auth_mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>mod_auth_mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:1002-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-1002.html"/>
        <reference source="CVE" ref_id="CVE-2008-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2384.html"/>
        <description>SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:26.468-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:20.917-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:43.350-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="mod_auth_mysql is earlier than 1:3.0.0-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:99710"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22104" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1819: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1819-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1819.html"/>
        <reference source="CESA" ref_id="CESA-2011:1819"/>
        <reference source="CVE" ref_id="CVE-2011-4539" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4539.html"/>
        <description>dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:25.580-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:20.824-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:43.243-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dhcp-devel is earlier than 12:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:98525"/>
          <criterion comment="dhclient is earlier than 12:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:98493"/>
          <criterion comment="dhcp is earlier than 12:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:98804"/>
          <criterion comment="dhcp-common is earlier than 12:4.1.1-25.P1.el6_2.1" test_ref="oval:org.mitre.oval:tst:98863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22102" version="198" class="patch">
      <metadata>
        <title>RHSA-2010:0867: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0867-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0867.html"/>
        <reference source="CVE" ref_id="CVE-2010-3636" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3636.html"/>
        <reference source="CVE" ref_id="CVE-2010-3639" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3639.html"/>
        <reference source="CVE" ref_id="CVE-2010-3640" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3640.html"/>
        <reference source="CVE" ref_id="CVE-2010-3641" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3641.html"/>
        <reference source="CVE" ref_id="CVE-2010-3642" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3642.html"/>
        <reference source="CVE" ref_id="CVE-2010-3643" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3643.html"/>
        <reference source="CVE" ref_id="CVE-2010-3644" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3644.html"/>
        <reference source="CVE" ref_id="CVE-2010-3645" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3645.html"/>
        <reference source="CVE" ref_id="CVE-2010-3646" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3646.html"/>
        <reference source="CVE" ref_id="CVE-2010-3647" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3647.html"/>
        <reference source="CVE" ref_id="CVE-2010-3648" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3648.html"/>
        <reference source="CVE" ref_id="CVE-2010-3649" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3649.html"/>
        <reference source="CVE" ref_id="CVE-2010-3650" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3650.html"/>
        <reference source="CVE" ref_id="CVE-2010-3652" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3652.html"/>
        <reference source="CVE" ref_id="CVE-2010-3654" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3654.html"/>
        <description>Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:33.331-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:20.423-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:42.829-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:10.1.102.64-1.el6" test_ref="oval:org.mitre.oval:tst:99518"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22097" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0979: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0979-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0979.html"/>
        <reference source="CVE" ref_id="CVE-2010-4180" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4180.html"/>
        <description>OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:42.434-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:19.442-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:41.950-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl-devel is earlier than 0:1.0.0-4.el6_0.2" test_ref="oval:org.mitre.oval:tst:99143"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-4.el6_0.2" test_ref="oval:org.mitre.oval:tst:99950"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-4.el6_0.2" test_ref="oval:org.mitre.oval:tst:99798"/>
          <criterion comment="openssl is earlier than 0:1.0.0-4.el6_0.2" test_ref="oval:org.mitre.oval:tst:99985"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22095" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1132: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1132.html"/>
        <reference source="CESA" ref_id="CESA-2011:1132"/>
        <reference source="CVE" ref_id="CVE-2011-2200" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2200.html"/>
        <description>The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-native byte order, which allows local users to cause a denial of service (connection loss), obtain potentially sensitive information, or conduct unspecified state-modification attacks via crafted messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:14.978-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:19.349-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:41.858-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-devel is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:98328"/>
            <criterion comment="dbus is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:98336"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:98184"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-16.el5_7" test_ref="oval:org.mitre.oval:tst:98270"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-devel is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:98037"/>
            <criterion comment="dbus is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:98321"/>
            <criterion comment="dbus-x11 is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:98046"/>
            <criterion comment="dbus-libs is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:98018"/>
            <criterion comment="dbus-doc is earlier than 1:1.2.24-5.el6_1" test_ref="oval:org.mitre.oval:tst:97803"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22092" version="87" class="patch">
      <metadata>
        <title>RHSA-2014:0136: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0136-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0136.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0417.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:21.283-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:37.818-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:15.848-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22092 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:18.268-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:11.292-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22092 - Added criteria for RHEL 5 and 7" date="2015-07-13T20:25:00.758-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-07-13T20:27:40.947-04:00">INTERIM</status_change>
            <status_change date="2015-08-03T04:01:29.515-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140911"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140690"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141017"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141058"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141222"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141185"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:141143"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:140793"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100347"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100452"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100222"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100379"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100372"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:100369"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" test_ref="oval:org.mitre.oval:tst:99973"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22085" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1323: qt security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1323-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1323.html"/>
        <reference source="CVE" ref_id="CVE-2011-3193" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3193.html"/>
        <reference source="CVE" ref_id="CVE-2011-3194" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3194.html"/>
        <description>Buffer overflow in the TIFF reader in gui/image/qtiffhandler.cpp in Qt 4.7.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the TIFFTAG_SAMPLESPERPIXEL tag in a greyscale TIFF image with multiple samples per pixel.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:25.219-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:18.024-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:40.404-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qt-demos is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:98100"/>
          <criterion comment="qt-odbc is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:98110"/>
          <criterion comment="qt-mysql is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:98545"/>
          <criterion comment="qt-doc is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:98472"/>
          <criterion comment="qt-x11 is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:98524"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:98479"/>
          <criterion comment="qt-postgresql is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:98147"/>
          <criterion comment="qt-sqlite is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:98471"/>
          <criterion comment="qt is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:98485"/>
          <criterion comment="qt-examples is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:98354"/>
          <criterion comment="qt-devel is earlier than 1:4.6.2-17.el6_1.1" test_ref="oval:org.mitre.oval:tst:97678"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22078" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1424: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1424-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1424.html"/>
        <reference source="CVE" ref_id="CVE-2011-2939" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2939.html"/>
        <reference source="CVE" ref_id="CVE-2011-3597" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3597.html"/>
        <description>Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arbitrary commands via the new constructor.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:19.457-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:17.588-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:39.837-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="perl-libs is earlier than 4:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98682"/>
          <criterion comment="perl-suidperl is earlier than 4:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98339"/>
          <criterion comment="perl-core is earlier than 0:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98624"/>
          <criterion comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98680"/>
          <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98081"/>
          <criterion comment="perl-Package-Constants is earlier than 1:0.02-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98517"/>
          <criterion comment="perl-CGI is earlier than 0:3.51-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98093"/>
          <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98410"/>
          <criterion comment="perl-version is earlier than 3:0.77-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98597"/>
          <criterion comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98725"/>
          <criterion comment="perl-Time-HiRes is earlier than 4:1.9721-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98507"/>
          <criterion comment="perl-Archive-Extract is earlier than 1:0.38-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98135"/>
          <criterion comment="perl-Test-Simple is earlier than 0:0.92-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98302"/>
          <criterion comment="perl-Module-Loaded is earlier than 1:0.02-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98656"/>
          <criterion comment="perl-Compress-Raw-Zlib is earlier than 0:2.023-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:97904"/>
          <criterion comment="perl-Pod-Escapes is earlier than 1:1.04-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98368"/>
          <criterion comment="perl-CPANPLUS is earlier than 0:0.88-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98688"/>
          <criterion comment="perl-parent is earlier than 1:0.221-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98520"/>
          <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98747"/>
          <criterion comment="perl-Module-Pluggable is earlier than 1:3.90-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98205"/>
          <criterion comment="perl-Test-Harness is earlier than 0:3.17-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98523"/>
          <criterion comment="perl-Module-Load is earlier than 1:0.16-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98701"/>
          <criterion comment="perl-Pod-Simple is earlier than 1:3.13-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98210"/>
          <criterion comment="perl-Params-Check is earlier than 1:0.26-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98704"/>
          <criterion comment="perl-File-Fetch is earlier than 0:0.26-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98491"/>
          <criterion comment="perl-IO-Zlib is earlier than 1:1.09-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98399"/>
          <criterion comment="perl-Module-CoreList is earlier than 0:2.18-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98601"/>
          <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98648"/>
          <criterion comment="perl is earlier than 4:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98504"/>
          <criterion comment="perl-Time-Piece is earlier than 0:1.15-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98427"/>
          <criterion comment="perl-Digest-SHA is earlier than 1:5.47-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:97972"/>
          <criterion comment="perl-Archive-Tar is earlier than 0:1.58-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98370"/>
          <criterion comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98196"/>
          <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98112"/>
          <criterion comment="perl-devel is earlier than 4:5.10.1-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98679"/>
          <criterion comment="perl-CPAN is earlier than 0:1.9402-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98204"/>
          <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:97766"/>
          <criterion comment="perl-Object-Accessor is earlier than 1:0.34-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98023"/>
          <criterion comment="perl-IPC-Cmd is earlier than 1:0.56-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98713"/>
          <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98677"/>
          <criterion comment="perl-Term-UI is earlier than 0:0.20-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98514"/>
          <criterion comment="perl-Module-Build is earlier than 1:0.3500-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98691"/>
          <criterion comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98730"/>
          <criterion comment="perl-Log-Message is earlier than 1:0.02-119.el6_1.1" test_ref="oval:org.mitre.oval:tst:98683"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22075" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1508: cyrus-imapd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1508-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1508.html"/>
        <reference source="CESA" ref_id="CESA-2011:1508"/>
        <reference source="CVE" ref_id="CVE-2011-3372" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3372.html"/>
        <reference source="CVE" ref_id="CVE-2011-3481" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3481.html"/>
        <description>The index_get_ids function in index.c in imapd in Cyrus IMAP Server before 2.4.11, when server-side threading is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted References header in an e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:21.703-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:17.360-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:39.523-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:98879"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:98824"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:98303"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.2" test_ref="oval:org.mitre.oval:tst:98664"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:98492"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:98649"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.4" test_ref="oval:org.mitre.oval:tst:98654"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22072" version="68" class="patch">
      <metadata>
        <title>RHSA-2011:1342: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1342-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1342.html"/>
        <reference source="CVE" ref_id="CVE-2011-2372" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2372.html"/>
        <reference source="CVE" ref_id="CVE-2011-2995" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2995.html"/>
        <reference source="CVE" ref_id="CVE-2011-2998" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2998.html"/>
        <reference source="CVE" ref_id="CVE-2011-2999" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2999.html"/>
        <reference source="CVE" ref_id="CVE-2011-3000" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3000.html"/>
        <description>Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:19.034-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:17.077-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:39.226-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.15-1.el6_1" test_ref="oval:org.mitre.oval:tst:98404"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22071" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1243: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1243-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1243.html"/>
        <reference source="CESA" ref_id="CESA-2011:1243"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

It was found that a Certificate Authority (CA) issued a fraudulent HTTPS
certificate. This update renders any HTTPS certificates signed by that
CA as untrusted, except for a select few. The now untrusted certificates
that were issued before July 1, 2011 can be manually re-enabled and used
again at your own risk in Thunderbird; however, affected certificates
issued after this date cannot be re-enabled or used. (BZ#734316)

All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:17.510-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:16.987-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:39.160-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22071 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:40.846-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:45.918-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-24.el5" test_ref="oval:org.mitre.oval:tst:98185"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:3.1.12-2.el6_1" test_ref="oval:org.mitre.oval:tst:98102"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22070" version="107" class="patch">
      <metadata>
        <title>RHSA-2010:0896: thunderbird security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0896-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0896.html"/>
        <reference source="CVE" ref_id="CVE-2010-3175" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3175.html"/>
        <reference source="CVE" ref_id="CVE-2010-3176" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3176.html"/>
        <reference source="CVE" ref_id="CVE-2010-3178" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3178.html"/>
        <reference source="CVE" ref_id="CVE-2010-3179" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3179.html"/>
        <reference source="CVE" ref_id="CVE-2010-3180" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3180.html"/>
        <reference source="CVE" ref_id="CVE-2010-3182" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3182.html"/>
        <reference source="CVE" ref_id="CVE-2010-3183" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3183.html"/>
        <reference source="CVE" ref_id="CVE-2010-3765" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3765.html"/>
        <description>Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:33.935-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:16.718-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:38.876-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.6-1.el6_0" test_ref="oval:org.mitre.oval:tst:99991"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22064" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1247: rsyslog security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>rsyslog</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1247-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1247.html"/>
        <reference source="CVE" ref_id="CVE-2011-3200" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3200.html"/>
        <description>Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before 4.6.8 and 5.2.0 through 5.8.4 might allow remote attackers to cause a denial of service (application exit) via a long TAG in a legacy syslog message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:46.513-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:16.635-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:38.789-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="rsyslog-relp is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:98028"/>
          <criterion comment="rsyslog-gssapi is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:98061"/>
          <criterion comment="rsyslog-gnutls is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:98310"/>
          <criterion comment="rsyslog-pgsql is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:98032"/>
          <criterion comment="rsyslog is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:97882"/>
          <criterion comment="rsyslog-mysql is earlier than 0:4.6.2-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:98130"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22062" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1154: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1154-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1154.html"/>
        <reference source="CESA" ref_id="CESA-2011:1154"/>
        <reference source="CVE" ref_id="CVE-2011-2895" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2895.html"/>
        <description>The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly handle code words that are absent from the decompression table when encountered, which allows context-dependent attackers to trigger an infinite loop or a heap-based buffer overflow, and possibly execute arbitrary code, via a crafted compressed stream, a related issue to CVE-2006-1168 and CVE-2011-2896.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:58.917-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:16.083-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:38.288-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:98313"/>
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.4.el5_7" test_ref="oval:org.mitre.oval:tst:97879"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libXfont is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:98314"/>
            <criterion comment="libXfont-devel is earlier than 0:1.4.1-2.el6_1" test_ref="oval:org.mitre.oval:tst:98105"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22060" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1849: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1849-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1849.html"/>
        <reference source="CESA" ref_id="CESA-2011:1849"/>
        <reference source="CVE" ref_id="CVE-2011-4127" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4127.html"/>
        <reference source="CVE" ref_id="CVE-2011-4621" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4621.html"/>
        <description>The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization, which allows local users to cause a denial of service (system hang) via an application that executes code in a loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:48.668-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:15.971-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:38.136-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98943"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98997"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98261"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98238"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98436"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98055"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98920"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98921"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:99017"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98999"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98678"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.2.1.el6" test_ref="oval:org.mitre.oval:tst:98849"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22055" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0919: qemu-kvm security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0919-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0919.html"/>
        <reference source="CVE" ref_id="CVE-2011-2212" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2212.html"/>
        <reference source="CVE" ref_id="CVE-2011-2512" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2512.html"/>
        <description>The virtio_queue_notify in qemu-kvm 0.14.0 and earlier does not properly validate the virtqueue number, which allows guest users to cause a denial of service (guest crash) and possibly execute arbitrary code via a negative number in the Queue Notify field of the Virtio Header, which bypasses a signed comparison.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:51.853-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:15.674-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:37.795-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.160.el6_1.2" test_ref="oval:org.mitre.oval:tst:97674"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.160.el6_1.2" test_ref="oval:org.mitre.oval:tst:98223"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.160.el6_1.2" test_ref="oval:org.mitre.oval:tst:98097"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22054" version="185" class="patch">
      <metadata>
        <title>RHSA-2011:1189: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1189-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1189.html"/>
        <reference source="CVE" ref_id="CVE-2011-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1182.html"/>
        <reference source="CVE" ref_id="CVE-2011-1576" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1576.html"/>
        <reference source="CVE" ref_id="CVE-2011-1593" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1593.html"/>
        <reference source="CVE" ref_id="CVE-2011-1776" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1776.html"/>
        <reference source="CVE" ref_id="CVE-2011-1898" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1898.html"/>
        <reference source="CVE" ref_id="CVE-2011-2183" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2183.html"/>
        <reference source="CVE" ref_id="CVE-2011-2213" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2213.html"/>
        <reference source="CVE" ref_id="CVE-2011-2491" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2491.html"/>
        <reference source="CVE" ref_id="CVE-2011-2492" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2492.html"/>
        <reference source="CVE" ref_id="CVE-2011-2495" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2495.html"/>
        <reference source="CVE" ref_id="CVE-2011-2497" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2497.html"/>
        <reference source="CVE" ref_id="CVE-2011-2517" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2517.html"/>
        <reference source="CVE" ref_id="CVE-2011-2689" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2689.html"/>
        <reference source="CVE" ref_id="CVE-2011-2695" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2695.html"/>
        <description>Multiple off-by-one errors in the ext4 subsystem in the Linux kernel before 3.0-rc5 allow local users to cause a denial of service (BUG_ON and system crash) by accessing a sparse file in extent format with a write operation involving a block number corresponding to the largest possible 32-bit unsigned integer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:51.120-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:15.260-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:37.313-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:98292"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:98073"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:98198"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:97938"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:98355"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:98383"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:98229"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:97742"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:98165"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:98068"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.12.1.el6" test_ref="oval:org.mitre.oval:tst:98280"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22052" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0959: mutt security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>mutt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0959-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0959.html"/>
        <reference source="CVE" ref_id="CVE-2011-1429" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1429.html"/>
        <description>Mutt does not verify that the smtps server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof an SSL SMTP server via an arbitrary certificate, a different vulnerability than CVE-2009-3766.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:53.048-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:14.371-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:36.223-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="mutt is earlier than 5:1.5.20-2.20091214hg736b6a.el6_1.1" test_ref="oval:org.mitre.oval:tst:98138"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22050" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0894: systemtap security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0894-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0894.html"/>
        <reference source="CESA" ref_id="CESA-2010:0894"/>
        <reference source="CVE" ref_id="CVE-2010-4170" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4170.html"/>
        <reference source="CVE" ref_id="CVE-2010-4171" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4171.html"/>
        <description>The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local users to cause a denial of service (unloading of arbitrary kernel modules).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:28.024-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.991-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:36.064-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="systemtap-client is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99854"/>
            <criterion comment="systemtap-runtime is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99981"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99942"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:100006"/>
            <criterion comment="systemtap is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99833"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99969"/>
            <criterion comment="systemtap-server is earlier than 0:1.1-3.el5_5.3" test_ref="oval:org.mitre.oval:tst:99936"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="systemtap-runtime is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99849"/>
            <criterion comment="systemtap-client is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99847"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99852"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99935"/>
            <criterion comment="systemtap is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99429"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99529"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99939"/>
            <criterion comment="systemtap-server is earlier than 0:1.2-11.el6_0" test_ref="oval:org.mitre.oval:tst:99908"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22040" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1282: nss and nspr security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-tools</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1282-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1282.html"/>
        <reference source="CESA" ref_id="CESA-2011:1282"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.

Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities.

It was found that a Certificate Authority (CA) issued fraudulent HTTPS
certificates. This update renders any HTTPS certificates signed by that CA
as untrusted. This covers all uses of the certificates, including SSL,
S/MIME, and code signing. (BZ#734316)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

These updated packages upgrade NSS to version 3.12.10 on Red Hat Enterprise
Linux 4 and 5. As well, they upgrade NSPR to version 4.8.8 on Red Hat
Enterprise Linux 4 and 5, as required by the NSS update. The packages for
Red Hat Enterprise Linux 6 include a backported patch.

All NSS and NSPR users should upgrade to these updated packages, which
correct this issue. After installing the update, applications using NSS and
NSPR must be restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:22.516-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.466-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:35.154-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22040 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:41.766-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:42.231-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nspr is earlier than 0:4.8.8-1.el5_7" test_ref="oval:org.mitre.oval:tst:98459"/>
            <criterion comment="nspr-devel is earlier than 0:4.8.8-1.el5_7" test_ref="oval:org.mitre.oval:tst:98043"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:98470"/>
            <criterion comment="nss-tools is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:98343"/>
            <criterion comment="nss is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:98293"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-4.el5_7" test_ref="oval:org.mitre.oval:tst:98362"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:98140"/>
            <criterion comment="nss-tools is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:98271"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:98482"/>
            <criterion comment="nss is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:98530"/>
            <criterion comment="nss-devel is earlier than 0:3.12.9-12.el6_1" test_ref="oval:org.mitre.oval:tst:98382"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22039" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:1333: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1333-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1333.html"/>
        <reference source="CVE" ref_id="CVE-2011-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2426.html"/>
        <reference source="CVE" ref_id="CVE-2011-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2427.html"/>
        <reference source="CVE" ref_id="CVE-2011-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2428.html"/>
        <reference source="CVE" ref_id="CVE-2011-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2429.html"/>
        <reference source="CVE" ref_id="CVE-2011-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2430.html"/>
        <reference source="CVE" ref_id="CVE-2011-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2444.html"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to inject arbitrary web script or HTML via a crafted URL, related to a "universal cross-site scripting issue," as exploited in the wild in September 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:14.771-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:13.289-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:34.912-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el5" test_ref="oval:org.mitre.oval:tst:98478"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.10-1.el6" test_ref="oval:org.mitre.oval:tst:98466"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22025" version="6" class="patch">
      <metadata>
        <title>RHSA-2014:0044: augeas security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>augeas</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0044-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0044.html"/>
        <reference source="CESA" ref_id="CESA-2014:0044"/>
        <reference source="CVE" ref_id="CVE-2013-6412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6412.html"/>
        <description>The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-28T12:16:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-11T14:03:38.827-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:02.932-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:32.340-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22025 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:31:00.517-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:32:52.838-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:10.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="augeas-libs is earlier than 0:1.0.0-5.el6_5.1" test_ref="oval:org.mitre.oval:tst:100284"/>
          <criterion comment="augeas is earlier than 0:1.0.0-5.el6_5.1" test_ref="oval:org.mitre.oval:tst:99896"/>
          <criterion comment="augeas-devel is earlier than 0:1.0.0-5.el6_5.1" test_ref="oval:org.mitre.oval:tst:100343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22018" version="44" class="patch">
      <metadata>
        <title>RHSA-2014:0015: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0015-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0015.html"/>
        <reference source="CESA" ref_id="CESA-2014:0015"/>
        <reference source="CVE" ref_id="CVE-2013-4353" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4353.html"/>
        <reference source="CVE" ref_id="CVE-2013-6449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6449.html"/>
        <reference source="CVE" ref_id="CVE-2013-6450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6450.html"/>
        <description>The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:58:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:42:30.318-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.970-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:32.916-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22018 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:38.474-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:41.947-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:99015"/>
          <criterion comment="openssl is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:98888"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:98928"/>
          <criterion comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.4" test_ref="oval:org.mitre.oval:tst:98827"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22017" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:1379: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1379-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1379.html"/>
        <reference source="CVE" ref_id="CVE-2011-1527" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1527.html"/>
        <reference source="CVE" ref_id="CVE-2011-1528" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1528.html"/>
        <reference source="CVE" ref_id="CVE-2011-1529" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1529.html"/>
        <description>The lookup_lockout_policy function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8 through 1.8.4 and 1.9 through 1.9.1, when the db2 (aka Berkeley DB) or LDAP back end is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger certain process_as_req errors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:50.779-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.870-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:32.760-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-devel is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98647"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98596"/>
          <criterion comment="krb5-workstation is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98584"/>
          <criterion comment="krb5-libs is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98573"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98259"/>
          <criterion comment="krb5-server is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98298"/>
          <criterion comment="krb5 is earlier than 0:1.9-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98325"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22016" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1317: cyrus-imapd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1317-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1317.html"/>
        <reference source="CESA" ref_id="CESA-2011:1317"/>
        <reference source="CVE" ref_id="CVE-2011-3208" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3208.html"/>
        <description>Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remote attackers to execute arbitrary code via a crafted NNTP command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:08.834-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.791-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:32.637-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:97968"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:98476"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:98556"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.1" test_ref="oval:org.mitre.oval:tst:98033"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:98322"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:98340"/>
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:98308"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22011" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1455: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1455-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1455.html"/>
        <reference source="CESA" ref_id="CESA-2011:1455"/>
        <reference source="CVE" ref_id="CVE-2011-3439" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3439.html"/>
        <description>FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:10.802-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.557-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:32.313-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:98793"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:98461"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.2" test_ref="oval:org.mitre.oval:tst:98490"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:98666"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:98425"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.8" test_ref="oval:org.mitre.oval:tst:98484"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22009" version="237" class="patch">
      <metadata>
        <title>RHSA-2011:1384: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1384-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1384.html"/>
        <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html"/>
        <reference source="CVE" ref_id="CVE-2011-3516" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3516.html"/>
        <reference source="CVE" ref_id="CVE-2011-3521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3521.html"/>
        <reference source="CVE" ref_id="CVE-2011-3544" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3544.html"/>
        <reference source="CVE" ref_id="CVE-2011-3545" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3545.html"/>
        <reference source="CVE" ref_id="CVE-2011-3546" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3546.html"/>
        <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html"/>
        <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html"/>
        <reference source="CVE" ref_id="CVE-2011-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3549.html"/>
        <reference source="CVE" ref_id="CVE-2011-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3550.html"/>
        <reference source="CVE" ref_id="CVE-2011-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3551.html"/>
        <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html"/>
        <reference source="CVE" ref_id="CVE-2011-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3553.html"/>
        <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html"/>
        <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html"/>
        <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html"/>
        <reference source="CVE" ref_id="CVE-2011-3558" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3558.html"/>
        <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html"/>
        <reference source="CVE" ref_id="CVE-2011-3561" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3561.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:15.834-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:11.034-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:31.592-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98228"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98371"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98250"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98614"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97901"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98149"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98537"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97694"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98552"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98603"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97996"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98142"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22006" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0926: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0926-02" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0926.html"/>
        <reference source="CVE" ref_id="CVE-2011-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2464.html"/>
        <reference source="CESA-2011:0926" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-July/017643.html" ref_id="CESA-2011:0926-CentOS 5"/>
        <description>Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:43.018-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.838-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:31.365-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:22006 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:30.831-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:20.556-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind97 is earlier than 32:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:137289"/>
            <criterion comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:137856"/>
            <criterion comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:137804"/>
            <criterion comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:137380"/>
            <criterion comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_6.3" test_ref="oval:org.mitre.oval:tst:137574"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:98241"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:98104"/>
            <criterion comment="bind-debuginfo is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:137310"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:97731"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:97693"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:97308"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.2" test_ref="oval:org.mitre.oval:tst:97309"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22004" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1791: squid security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1791-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1791.html"/>
        <reference source="CESA" ref_id="CESA-2011:1791"/>
        <reference source="CVE" ref_id="CVE-2011-4096" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4096.html"/>
        <description>The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:26.289-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.772-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:31.275-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="squid is earlier than 7:3.1.10-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:98813"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22003" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0930: NetworkManager security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>NetworkManager</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0930-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0930.html"/>
        <reference source="CVE" ref_id="CVE-2011-2176" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2176.html"/>
        <description>GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:48.647-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.704-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:31.186-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="NetworkManager is earlier than 1:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:98253"/>
          <criterion comment="NetworkManager-devel is earlier than 1:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:98277"/>
          <criterion comment="NetworkManager-gnome is earlier than 1:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:97387"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 1:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:97993"/>
          <criterion comment="NetworkManager-glib is earlier than 1:0.8.1-9.el6_1.1" test_ref="oval:org.mitre.oval:tst:98282"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22002" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1245: httpd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1245-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1245.html"/>
        <reference source="CVE" ref_id="CVE-2011-3192" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3192.html"/>
        <description>The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than CVE-2007-0086.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:55.389-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.605-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:31.080-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:98455"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:97962"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:98060"/>
            <criterion comment="httpd is earlier than 0:2.2.3-53.el5_7.1" test_ref="oval:org.mitre.oval:tst:98451"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98331"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98122"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98374"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:98108"/>
            <criterion comment="httpd is earlier than 0:2.2.15-9.el6_1.2" test_ref="oval:org.mitre.oval:tst:97781"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21994" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1160: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1160-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1160.html"/>
        <reference source="CESA" ref_id="CESA-2011:1160"/>
        <reference source="CVE" ref_id="CVE-2011-2748" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2748.html"/>
        <reference source="CVE" ref_id="CVE-2011-2749" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2749.html"/>
        <description>The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial of service (daemon exit) via a crafted BOOTP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:59.187-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:10.240-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:30.597-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libdhcp4client is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:97914"/>
            <criterion comment="dhclient is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:98083"/>
            <criterion comment="dhcp-devel is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:98225"/>
            <criterion comment="dhcp is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:98139"/>
            <criterion comment="libdhcp4client-devel is earlier than 12:3.0.5-29.el5_7.1" test_ref="oval:org.mitre.oval:tst:98224"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dhclient is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:97580"/>
            <criterion comment="dhcp-devel is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98350"/>
            <criterion comment="dhcp is earlier than 12:4.1.1-19.P1.el6_1.1" test_ref="oval:org.mitre.oval:tst:97365"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21992" version="146" class="patch">
      <metadata>
        <title>RHSA-2011:1350: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1350-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1350.html"/>
        <reference source="CVE" ref_id="CVE-2011-1160" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1160.html"/>
        <reference source="CVE" ref_id="CVE-2011-1745" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1745.html"/>
        <reference source="CVE" ref_id="CVE-2011-1746" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1746.html"/>
        <reference source="CVE" ref_id="CVE-2011-1833" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1833.html"/>
        <reference source="CVE" ref_id="CVE-2011-2022" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2022.html"/>
        <reference source="CVE" ref_id="CVE-2011-2484" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2484.html"/>
        <reference source="CVE" ref_id="CVE-2011-2496" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2496.html"/>
        <reference source="CVE" ref_id="CVE-2011-2521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2521.html"/>
        <reference source="CVE" ref_id="CVE-2011-2723" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2723.html"/>
        <reference source="CVE" ref_id="CVE-2011-2898" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2898.html"/>
        <reference source="CVE" ref_id="CVE-2011-2918" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2918.html"/>
        <description>The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:01.411-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:09.983-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:30.229-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:98595"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:97989"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:98561"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:98535"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:98256"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:98375"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:98406"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:97881"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:98317"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:98257"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.17.1.el6" test_ref="oval:org.mitre.oval:tst:97710"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21990" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0924: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0924-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0924.html"/>
        <reference source="CVE" ref_id="CVE-2010-3445" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3445.html"/>
        <reference source="CVE" ref_id="CVE-2010-4300" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4300.html"/>
        <description>Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an LDSS packet with a long digest line that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:19.946-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:09.898-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:30.106-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="wireshark is earlier than 0:1.2.13-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:99663"/>
          <criterion comment="wireshark-devel is earlier than 0:1.2.13-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:99743"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.2.13-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:99502"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21988" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1293: squid security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1293-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1293.html"/>
        <reference source="CVE" ref_id="CVE-2011-3205" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3205.html"/>
        <description>Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response.  NOTE: This issue exists because of a CVE-2005-0094 regression.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:00.436-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:09.839-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:30.022-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="squid is earlier than 7:3.1.10-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98430"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21986" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0858: xerces-j2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>xerces-j2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0858-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0858.html"/>
        <reference source="CVE" ref_id="CVE-2009-2625" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2625.html"/>
        <description>XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:58.063-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:09.767-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:29.896-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:97371"/>
          <criterion comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:97783"/>
          <criterion comment="xerces-j2-demo is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:98027"/>
          <criterion comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:97434"/>
          <criterion comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:98126"/>
          <criterion comment="xerces-j2 is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:98136"/>
          <criterion comment="xerces-j2-scripts is earlier than 0:2.7.1-12.6.el6_0" test_ref="oval:org.mitre.oval:tst:97357"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21985" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1801: qemu-kvm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1801-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1801.html"/>
        <reference source="CESA" ref_id="CESA-2011:1801"/>
        <reference source="CVE" ref_id="CVE-2011-4111" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4111.html"/>
        <description>Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:11.940-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:09.697-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:29.785-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.160.el6_1.9" test_ref="oval:org.mitre.oval:tst:98781"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.160.el6_1.9" test_ref="oval:org.mitre.oval:tst:98895"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.160.el6_1.9" test_ref="oval:org.mitre.oval:tst:98882"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21984" version="185" class="patch">
      <metadata>
        <title>RHSA-2011:1144: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1144-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1144.html"/>
        <reference source="CVE" ref_id="CVE-2011-2130" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2130.html"/>
        <reference source="CVE" ref_id="CVE-2011-2134" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2134.html"/>
        <reference source="CVE" ref_id="CVE-2011-2135" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2135.html"/>
        <reference source="CVE" ref_id="CVE-2011-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2136.html"/>
        <reference source="CVE" ref_id="CVE-2011-2137" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2137.html"/>
        <reference source="CVE" ref_id="CVE-2011-2138" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2138.html"/>
        <reference source="CVE" ref_id="CVE-2011-2139" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2139.html"/>
        <reference source="CVE" ref_id="CVE-2011-2140" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2140.html"/>
        <reference source="CVE" ref_id="CVE-2011-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2414.html"/>
        <reference source="CVE" ref_id="CVE-2011-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2415.html"/>
        <reference source="CVE" ref_id="CVE-2011-2416" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2416.html"/>
        <reference source="CVE" ref_id="CVE-2011-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2417.html"/>
        <reference source="CVE" ref_id="CVE-2011-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2424.html"/>
        <reference source="CVE" ref_id="CVE-2011-2425" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2425.html"/>
        <description>Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2135, CVE-2011-2140, and CVE-2011-2417.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:58.021-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:09.389-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:29.361-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.5-1.el5" test_ref="oval:org.mitre.oval:tst:97648"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.5-1.el6" test_ref="oval:org.mitre.oval:tst:98123"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21983" version="42" class="patch">
      <metadata>
        <title>RHSA-2010:0925: krb5 security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0925-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0925.html"/>
        <reference source="CVE" ref_id="CVE-2010-1323" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1323.html"/>
        <reference source="CVE" ref_id="CVE-2010-1324" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1324.html"/>
        <reference source="CVE" ref_id="CVE-2010-4020" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4020.html"/>
        <description>MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (1) AD-SIGNEDPATH or (2) AD-KDC-ISSUED signature, and possibly gain privileges, by leveraging the small key space that results from certain one-byte stream-cipher operations.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:10.439-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:09.275-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:29.214-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:99027"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:99927"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:99061"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:99864"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:99748"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:99817"/>
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:100011"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21981" version="133" class="patch">
      <metadata>
        <title>RHSA-2011:0938: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0938-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0938.html"/>
        <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html"/>
        <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html"/>
        <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-0863" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0863.html"/>
        <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html"/>
        <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html"/>
        <reference source="CVE" ref_id="CVE-2011-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0868.html"/>
        <reference source="CVE" ref_id="CVE-2011-0869" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0869.html"/>
        <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html"/>
        <reference source="CVE" ref_id="CVE-2011-0873" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0873.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:15.995-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:08.965-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:28.740-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97311"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:98167"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:98087"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:98074"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97323"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97525"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97984"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:98262"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97888"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:98315"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:98127"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97859"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:98077"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97953"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:98162"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21976" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1187: dovecot security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>dovecot</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1187-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1187.html"/>
        <reference source="CESA" ref_id="CESA-2011:1187"/>
        <reference source="CVE" ref_id="CVE-2011-1929" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1929.html"/>
        <description>lib-mail/message-header-parser.c in Dovecot 1.2.x before 1.2.17 and 2.0.x before 2.0.13 does not properly handle '\0' characters in header names, which allows remote attackers to cause a denial of service (daemon crash or mailbox corruption) via a crafted e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:32.117-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:08.761-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:28.515-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="dovecot is earlier than 0:1.0.7-7.el5_7.1" test_ref="oval:org.mitre.oval:tst:98402"/>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98082"/>
            <criterion comment="dovecot-mysql is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98088"/>
            <criterion comment="dovecot is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98119"/>
            <criterion comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98363"/>
            <criterion comment="dovecot-devel is earlier than 1:2.0.9-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98243"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21975" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1533: ipa security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>ipa</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1533-04" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1533.html"/>
        <reference source="CVE" ref_id="CVE-2011-3636" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3636.html"/>
        <description>Cross-site request forgery (CSRF) vulnerability in the management interface in FreeIPA before 2.1.4 allows remote attackers to hijack the authentication of administrators for requests that make configuration changes.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:00.966-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:08.687-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:28.403-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ipa-python is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:98859"/>
          <criterion comment="ipa-admintools is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:98591"/>
          <criterion comment="ipa-client is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:98468"/>
          <criterion comment="ipa-server-selinux is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:98565"/>
          <criterion comment="ipa-server is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:98364"/>
          <criterion comment="ipa is earlier than 0:2.1.3-9.el6" test_ref="oval:org.mitre.oval:tst:98856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21968" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0928: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0928-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0928.html"/>
        <reference source="CVE" ref_id="CVE-2011-1767" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1767.html"/>
        <reference source="CVE" ref_id="CVE-2011-1768" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1768.html"/>
        <reference source="CVE" ref_id="CVE-2011-2479" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2479.html"/>
        <description>The Linux kernel before 2.6.39 does not properly create transparent huge pages in response to a MAP_PRIVATE mmap system call on /dev/zero, which allows local users to cause a denial of service (system crash) via a crafted application.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:34.125-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:08.456-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:28.098-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:97921"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:98030"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:98232"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:98255"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:98295"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:98236"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:98273"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:98251"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:97728"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:98286"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.6.1.el6" test_ref="oval:org.mitre.oval:tst:98290"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21963" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0871: tigervnc security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>tigervnc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0871-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0871.html"/>
        <reference source="CVE" ref_id="CVE-2011-1775" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1775.html"/>
        <description>The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:00.746-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:07.540-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:27.252-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tigervnc-server-module is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:97645"/>
          <criterion comment="tigervnc is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:97963"/>
          <criterion comment="tigervnc-server is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:97471"/>
          <criterion comment="tigervnc-server-applet is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" test_ref="oval:org.mitre.oval:tst:98252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21961" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1267: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1267-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1267.html"/>
        <reference source="CESA" ref_id="CESA-2011:1267"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

The RHSA-2011:1243 Thunderbird update rendered HTTPS certificates signed by
a certain Certificate Authority (CA) as untrusted, but made an exception
for a select few. This update removes that exception, rendering every HTTPS
certificate signed by that CA as untrusted. (BZ#735483)

All Thunderbird users should upgrade to this updated package, which
resolves this issue. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:02.709-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:07.482-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:27.181-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21961 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:39.221-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:41.839-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-25.el5" test_ref="oval:org.mitre.oval:tst:97929"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:3.1.14-1.el6_1" test_ref="oval:org.mitre.oval:tst:97563"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21959" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1248: ca-certificates security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>ca-certificates</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1248-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1248.html"/>
        <description>This package contains the set of CA certificates chosen by the Mozilla
Foundation for use with the Internet Public Key Infrastructure (PKI).

It was found that a Certificate Authority (CA) issued fraudulent HTTPS
certificates. This update removes that CA's root certificate from the
ca-certificates package, rendering any HTTPS certificates signed by that CA
as untrusted. (BZ#734381)

All users should upgrade to this updated package. After installing the
update, all applications using the ca-certificates package must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:28.365-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:07.338-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:27.017-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21959 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:37.884-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:41.749-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="ca-certificates is earlier than 0:2010.63-3.el6_1.5" test_ref="oval:org.mitre.oval:tst:97850"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21957" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0406: quagga security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>quagga</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0406-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0406.html"/>
        <reference source="CVE" ref_id="CVE-2010-1674" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1674.html"/>
        <reference source="CVE" ref_id="CVE-2010-1675" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1675.html"/>
        <description>bgpd in Quagga before 0.99.18 allows remote attackers to cause a denial of service (session reset) via a malformed AS_PATHLIMIT path attribute.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:30.486-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:07.245-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:26.912-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="quagga-devel is earlier than 0:0.99.15-5.el6_0.2" test_ref="oval:org.mitre.oval:tst:97617"/>
          <criterion comment="quagga-contrib is earlier than 0:0.99.15-5.el6_0.2" test_ref="oval:org.mitre.oval:tst:97438"/>
          <criterion comment="quagga is earlier than 0:0.99.15-5.el6_0.2" test_ref="oval:org.mitre.oval:tst:96846"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21956" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0791: tomcat6 security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0791-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0791.html"/>
        <reference source="CVE" ref_id="CVE-2010-3718" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3718.html"/>
        <reference source="CVE" ref_id="CVE-2010-4172" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4172.html"/>
        <reference source="CVE" ref_id="CVE-2011-0013" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0013.html"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-name tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:01.369-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:07.123-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:26.770-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:97837"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:98053"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:98042"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:98015"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:97643"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:97473"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:97288"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:97776"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-33.el6" test_ref="oval:org.mitre.oval:tst:97499"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21952" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0452: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0452-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0452.html"/>
        <reference source="CVE" ref_id="CVE-2009-5022" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5022.html"/>
        <description>Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:23.866-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:06.747-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:26.367-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libtiff is earlier than 0:3.9.4-1.el6_0.3" test_ref="oval:org.mitre.oval:tst:97686"/>
          <criterion comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.3" test_ref="oval:org.mitre.oval:tst:97433"/>
          <criterion comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.3" test_ref="oval:org.mitre.oval:tst:97675"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21951" version="55" class="patch">
      <metadata>
        <title>RHSA-2010:0892: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0892-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0892.html"/>
        <reference source="CVE" ref_id="CVE-2010-3302" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3302.html"/>
        <reference source="CVE" ref_id="CVE-2010-3308" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3308.html"/>
        <reference source="CVE" ref_id="CVE-2010-3752" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3752.html"/>
        <reference source="CVE" ref_id="CVE-2010-3753" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3753.html"/>
        <description>programs/pluto/xauth.c in the client in Openswan 2.6.26 through 2.6.28 allows remote authenticated gateways to execute arbitrary commands via shell metacharacters in the cisco_banner (aka server_banner) field, a different vulnerability than CVE-2010-3308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:55.018-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:06.603-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:26.213-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openswan is earlier than 0:2.6.24-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:100008"/>
          <criterion comment="openswan-doc is earlier than 0:2.6.24-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:99839"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21950" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1402: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1402-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1402.html"/>
        <reference source="CESA" ref_id="CESA-2011:1402"/>
        <reference source="CVE" ref_id="CVE-2011-3256" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3256.html"/>
        <description>FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font, a different vulnerability than CVE-2011-0226.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:06.540-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:06.500-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:26.110-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:98660"/>
            <criterion comment="freetype is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:98536"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.1" test_ref="oval:org.mitre.oval:tst:98188"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:98700"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:98065"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.7" test_ref="oval:org.mitre.oval:tst:98563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21949" version="55" class="patch">
      <metadata>
        <title>RHSA-2011:0839: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0839-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0839.html"/>
        <reference source="CVE" ref_id="CVE-2010-4540" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4540.html"/>
        <reference source="CVE" ref_id="CVE-2010-4541" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4541.html"/>
        <reference source="CVE" ref_id="CVE-2010-4542" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4542.html"/>
        <reference source="CVE" ref_id="CVE-2010-4543" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4543.html"/>
        <description>Heap-based buffer overflow in the read_channel_data function in file-psp.c in the Paint Shop Pro (PSP) plugin in GIMP 2.6.11 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a PSP_COMP_RLE (aka RLE compression) image file that begins a long run count at the end of the image.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:48.186-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:06.363-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:25.954-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gimp-libs is earlier than 2:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:98008"/>
          <criterion comment="gimp-devel is earlier than 2:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:98036"/>
          <criterion comment="gimp-help-browser is earlier than 2:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:97987"/>
          <criterion comment="gimp is earlier than 2:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:97692"/>
          <criterion comment="gimp-devel-tools is earlier than 2:2.6.9-4.el6_1.1" test_ref="oval:org.mitre.oval:tst:98062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21947" version="146" class="patch">
      <metadata>
        <title>RHSA-2010:0966: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0966-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0966.html"/>
        <reference source="CVE" ref_id="CVE-2010-3766" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3766.html"/>
        <reference source="CVE" ref_id="CVE-2010-3767" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3767.html"/>
        <reference source="CVE" ref_id="CVE-2010-3768" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3768.html"/>
        <reference source="CVE" ref_id="CVE-2010-3770" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3770.html"/>
        <reference source="CVE" ref_id="CVE-2010-3771" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3771.html"/>
        <reference source="CVE" ref_id="CVE-2010-3772" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3772.html"/>
        <reference source="CVE" ref_id="CVE-2010-3773" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3773.html"/>
        <reference source="CVE" ref_id="CVE-2010-3774" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3774.html"/>
        <reference source="CVE" ref_id="CVE-2010-3775" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3775.html"/>
        <reference source="CVE" ref_id="CVE-2010-3776" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3776.html"/>
        <reference source="CVE" ref_id="CVE-2010-3777" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3777.html"/>
        <description>Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:39.335-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:06.022-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:25.535-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el5" test_ref="oval:org.mitre.oval:tst:99608"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.13-3.el5" test_ref="oval:org.mitre.oval:tst:99983"/>
            <criterion comment="firefox is earlier than 0:3.6.13-2.el5" test_ref="oval:org.mitre.oval:tst:99947"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el6_0" test_ref="oval:org.mitre.oval:tst:100121"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.13-3.el6_0" test_ref="oval:org.mitre.oval:tst:100021"/>
            <criterion comment="firefox is earlier than 0:3.6.13-2.el6_0" test_ref="oval:org.mitre.oval:tst:100126"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21945" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0479: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0479-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0479.html"/>
        <reference source="CVE" ref_id="CVE-2011-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1486.html"/>
        <description>libvirtd in libvirt before 0.9.0 does not use thread-safe error reporting, which allows remote attackers to cause a denial of service (crash) by causing multiple threads to report errors at the same time.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:57.238-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:05.953-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:25.433-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.8.1-27.el6_0.6" test_ref="oval:org.mitre.oval:tst:97305"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.1-27.el6_0.6" test_ref="oval:org.mitre.oval:tst:97753"/>
          <criterion comment="libvirt-client is earlier than 0:0.8.1-27.el6_0.6" test_ref="oval:org.mitre.oval:tst:97555"/>
          <criterion comment="libvirt is earlier than 0:0.8.1-27.el6_0.6" test_ref="oval:org.mitre.oval:tst:97869"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21941" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1359: xorg-x11-server security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1359-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1359.html"/>
        <reference source="CESA" ref_id="CESA-2011:1359"/>
        <reference source="CVE" ref_id="CVE-2010-4818" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4818.html"/>
        <reference source="CVE" ref_id="CVE-2010-4819" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4819.html"/>
        <description>The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:50.531-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:05.293-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:24.262-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98548"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98052"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98513"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:97946"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98353"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98602"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98218"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.el5_7.5" test_ref="oval:org.mitre.oval:tst:98585"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98416"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98092"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98622"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98509"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:97660"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98366"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98518"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:97703"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.7.7-29.el6_1.2" test_ref="oval:org.mitre.oval:tst:98579"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21940" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0844: apr security update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>apr</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0844-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0844.html"/>
        <reference source="CESA" ref_id="CESA-2011:0844"/>
        <reference source="CVE" ref_id="CVE-2011-1928" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1928.html"/>
        <description>The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified types of wildcard patterns, as demonstrated by attacks against mod_autoindex in httpd when a /*/WEB-INF/ configuration pattern is used.  NOTE: this issue exists because of an incorrect fix for CVE-2011-0419.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:04.635-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:05.199-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:24.141-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:97722"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:98056"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_6.5" test_ref="oval:org.mitre.oval:tst:98041"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-devel is earlier than 0:1.3.9-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:97827"/>
            <criterion comment="apr is earlier than 0:1.3.9-3.el6_1.2" test_ref="oval:org.mitre.oval:tst:97916"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21939" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0372: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0372-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0372.html"/>
        <reference source="CVE" ref_id="CVE-2011-0609" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0609.html"/>
        <description>Unspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier on Android; Adobe AIR 2.5.1 and earlier; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader and Acrobat 9.x through 9.4.2 and 10.x through 10.0.1 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content, as demonstrated by a .swf file embedded in an Excel spreadsheet, and as exploited in the wild in March 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:30.268-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:05.119-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:24.051-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.153.1-1.el5" test_ref="oval:org.mitre.oval:tst:97654"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.2.153.1-1.el6" test_ref="oval:org.mitre.oval:tst:97632"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21938" version="71" class="patch">
      <metadata>
        <title>RHSA-2014:0164: mysql security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0164-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0164.html"/>
        <reference source="CESA" ref_id="CESA-2014:0164"/>
        <reference source="CVE" ref_id="CVE-2013-5908" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5908.html"/>
        <reference source="CVE" ref_id="CVE-2014-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0001.html"/>
        <reference source="CVE" ref_id="CVE-2014-0386" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0386.html"/>
        <reference source="CVE" ref_id="CVE-2014-0393" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0393.html"/>
        <reference source="CVE" ref_id="CVE-2014-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0401.html"/>
        <reference source="CVE" ref_id="CVE-2014-0402" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0402.html"/>
        <reference source="CVE" ref_id="CVE-2014-0412" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0412.html"/>
        <reference source="CVE" ref_id="CVE-2014-0437" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0437.html"/>
        <description>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.72 and earlier, 5.5.34 and earlier, and 5.6.14 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:17.898-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:36.003-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:13.113-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21938 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:16.792-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:09.914-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21938 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:38.863-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:52.572-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-devel is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:100580"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:100624"/>
          <criterion comment="mysql-test is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:100589"/>
          <criterion comment="mysql-server is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:100277"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:100506"/>
          <criterion comment="mysql is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:100202"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:100229"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.73-3.el6_5" test_ref="oval:org.mitre.oval:tst:100043"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21934" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0465: kdenetwork security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kdenetwork</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0465-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0465.html"/>
        <reference source="CVE" ref_id="CVE-2011-1586" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1586.html"/>
        <description>Directory traversal vulnerability in the KGetMetalink::File::isValidNameAttr function in ui/metalinkcreator/metalinker.cpp in KGet in KDE SC 4.6.2 and earlier allows remote attackers to create arbitrary files via a .. (dot dot) in the name attribute of a file element in a metalink file.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-1000.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:32.635-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:04.360-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:23.510-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kdenetwork-libs is earlier than 7:4.3.4-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:96887"/>
          <criterion comment="kdenetwork-devel is earlier than 7:4.3.4-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:97550"/>
          <criterion comment="kdenetwork is earlier than 7:4.3.4-11.el6_0.1" test_ref="oval:org.mitre.oval:tst:97457"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21933" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1102: libsoup security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libsoup</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1102-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1102.html"/>
        <reference source="CVE" ref_id="CVE-2011-2524" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2524.html"/>
        <description>Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:08.232-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:04.211-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:23.407-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libsoup-devel is earlier than 0:2.28.2-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98203"/>
          <criterion comment="libsoup is earlier than 0:2.28.2-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:97745"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21932" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1338: NetworkManager security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>NetworkManager</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1338-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1338.html"/>
        <reference source="CVE" ref_id="CVE-2011-3364" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3364.html"/>
        <description>Incomplete blacklist vulnerability in the svEscape function in settings/plugins/ifcfg-rh/shvar.c in the ifcfg-rh plug-in for GNOME NetworkManager 0.9.1, 0.9.0, 0.8.1, and possibly other versions, when PolicyKit is configured to allow users to create new connections, allows local users to execute arbitrary commands via a newline character in the name for a new network connection, which is not properly handled when writing to the ifcfg file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:16.627-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:04.126-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:23.312-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="NetworkManager is earlier than 1:0.8.1-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:98582"/>
          <criterion comment="NetworkManager-devel is earlier than 1:0.8.1-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:98319"/>
          <criterion comment="NetworkManager-gnome is earlier than 1:0.8.1-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:98403"/>
          <criterion comment="NetworkManager-glib is earlier than 1:0.8.1-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:98589"/>
          <criterion comment="NetworkManager-glib-devel is earlier than 1:0.8.1-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:97979"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21931" version="83" class="patch">
      <metadata>
        <title>RHSA-2011:0281: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0281-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0281.html"/>
        <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html"/>
        <reference source="CVE" ref_id="CVE-2010-4450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4450.html"/>
        <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html"/>
        <reference source="CVE" ref_id="CVE-2010-4469" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4469.html"/>
        <reference source="CVE" ref_id="CVE-2010-4470" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4470.html"/>
        <reference source="CVE" ref_id="CVE-2010-4472" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4472.html"/>
        <reference source="CESA-2011:0281" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017313.html" ref_id="CESA-2011:0281-CentOS 5"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs.  NOTE: the previous information was obtained from the February 2011 CPU.  Oracle has not commented on claims from a downstream vendor that this issue involves the replacement of the "XML DSig Transform or C14N algorithm implementations."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:54.841-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:03.920-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:23.024-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21931 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:23.744-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:19.756-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.20.b17.el5" test_ref="oval:org.mitre.oval:tst:137485"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.20.b17.el5" test_ref="oval:org.mitre.oval:tst:137829"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.20.b17.el5" test_ref="oval:org.mitre.oval:tst:137774"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.20.b17.el5" test_ref="oval:org.mitre.oval:tst:137864"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.20.b17.el5" test_ref="oval:org.mitre.oval:tst:137586"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97082"/>
            <criterion comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:137660"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:96965"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97425"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97074"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.39.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97073"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21930" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0395: gdm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>gdm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0395-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0395.html"/>
        <reference source="CVE" ref_id="CVE-2011-0727" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0727.html"/>
        <description>GNOME Display Manager (gdm) 2.x before 2.32.1 allows local users to change the ownership of arbitrary files via a symlink attack on a (1) dmrc or (2) face icon file under /var/cache/gdm/.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:51.348-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:03.826-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:22.914-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gdm-user-switch-applet is earlier than 1:2.30.4-21.el6_0.1" test_ref="oval:org.mitre.oval:tst:97741"/>
          <criterion comment="gdm-plugin-smartcard is earlier than 1:2.30.4-21.el6_0.1" test_ref="oval:org.mitre.oval:tst:97415"/>
          <criterion comment="gdm is earlier than 1:2.30.4-21.el6_0.1" test_ref="oval:org.mitre.oval:tst:97604"/>
          <criterion comment="gdm-plugin-fingerprint is earlier than 1:2.30.4-21.el6_0.1" test_ref="oval:org.mitre.oval:tst:97623"/>
          <criterion comment="gdm-libs is earlier than 1:2.30.4-21.el6_0.1" test_ref="oval:org.mitre.oval:tst:97395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21929" version="3" class="patch">
      <metadata>
        <title>RHSA-2011:1444: nss security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1444-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1444.html"/>
        <reference source="CESA" ref_id="CESA-2011:1444"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the development of security-enabled client and server applications.

It was found that the Malaysia-based Digicert Sdn. Bhd. subordinate
Certificate Authority (CA) issued HTTPS certificates with weak keys. This
update renders any HTTPS certificates signed by that CA as untrusted. This
covers all uses of the certificates, including SSL, S/MIME, and code
signing. Note: Digicert Sdn. Bhd. is not the same company as found at
digicert.com. (BZ#751366)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

This update also fixes the following bug on Red Hat Enterprise Linux 5:

* When using mod_nss with the Apache HTTP Server, a bug in NSS on Red Hat
Enterprise Linux 5 resulted in file descriptors leaking each time the
Apache HTTP Server was restarted with the "service httpd reload" command.
This could have prevented the Apache HTTP Server from functioning properly
if all available file descriptors were consumed. (BZ#743508)

For Red Hat Enterprise Linux 6, these updated packages upgrade NSS to
version 3.12.10. As well, they upgrade NSPR (Netscape Portable Runtime) to
version 4.8.8 and nss-util to version 3.12.10 on Red Hat
Enterprise Linux 6, as required by the NSS update. (BZ#735972, BZ#736272,
BZ#735973)

All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect. In addition, on Red Hat
Enterprise Linux 6, applications using NSPR and nss-util must also be
restarted.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:00.628-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:03.737-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:22.804-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss-tools is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:97792"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:98627"/>
            <criterion comment="nss is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:98465"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-7.el5_7" test_ref="oval:org.mitre.oval:tst:98752"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss-tools is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:98434"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:98650"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:98789"/>
            <criterion comment="nss is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:98531"/>
            <criterion comment="nss-devel is earlier than 0:3.12.10-2.el6_1" test_ref="oval:org.mitre.oval:tst:98626"/>
            <criterion comment="nspr is earlier than 0:4.8.8-1.el6_1" test_ref="oval:org.mitre.oval:tst:98760"/>
            <criterion comment="nspr-devel is earlier than 0:4.8.8-1.el6_1" test_ref="oval:org.mitre.oval:tst:98738"/>
            <criterion comment="nss-util is earlier than 0:3.12.10-1.el6_1" test_ref="oval:org.mitre.oval:tst:98621"/>
            <criterion comment="nss-util-devel is earlier than 0:3.12.10-1.el6_1" test_ref="oval:org.mitre.oval:tst:98540"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21928" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1100: icedtea-web security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1100-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1100.html"/>
        <reference source="CVE" ref_id="CVE-2011-2513" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2513.html"/>
        <reference source="CVE" ref_id="CVE-2011-2514" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2514.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:22.411-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:03.637-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:22.652-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.0.4-2.el6_1" test_ref="oval:org.mitre.oval:tst:98296"/>
          <criterion comment="icedtea-web is earlier than 0:1.0.4-2.el6_1" test_ref="oval:org.mitre.oval:tst:98332"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21924" version="198" class="patch">
      <metadata>
        <title>RHSA-2011:0498: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0498-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0498.html"/>
        <reference source="CVE" ref_id="CVE-2010-4250" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4250.html"/>
        <reference source="CVE" ref_id="CVE-2010-4565" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4565.html"/>
        <reference source="CVE" ref_id="CVE-2010-4649" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4649.html"/>
        <reference source="CVE" ref_id="CVE-2011-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0006.html"/>
        <reference source="CVE" ref_id="CVE-2011-0711" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0711.html"/>
        <reference source="CVE" ref_id="CVE-2011-0712" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0712.html"/>
        <reference source="CVE" ref_id="CVE-2011-0726" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0726.html"/>
        <reference source="CVE" ref_id="CVE-2011-1013" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1013.html"/>
        <reference source="CVE" ref_id="CVE-2011-1016" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1016.html"/>
        <reference source="CVE" ref_id="CVE-2011-1019" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1019.html"/>
        <reference source="CVE" ref_id="CVE-2011-1044" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1044.html"/>
        <reference source="CVE" ref_id="CVE-2011-1079" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1079.html"/>
        <reference source="CVE" ref_id="CVE-2011-1080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1080.html"/>
        <reference source="CVE" ref_id="CVE-2011-1093" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1093.html"/>
        <reference source="CVE" ref_id="CVE-2011-1573" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1573.html"/>
        <description>net/sctp/sm_make_chunk.c in the Linux kernel before 2.6.34, when addip_enable and auth_enable are used, does not consider the amount of zero padding during calculation of chunk lengths for (1) INIT and (2) INIT ACK chunks, which allows remote attackers to cause a denial of service (OOPS) via crafted packet data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:33.395-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:02.976-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:21.745-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97824"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97787"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97326"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97830"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97715"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97593"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97621"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97829"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97363"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97775"/>
          <criterion comment="kernel is earlier than 0:2.6.32-71.29.1.el6" test_ref="oval:org.mitre.oval:tst:97644"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21922" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0534: qemu-kvm security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0534-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0534.html"/>
        <reference source="CVE" ref_id="CVE-2011-1750" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1750.html"/>
        <reference source="CVE" ref_id="CVE-2011-1751" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1751.html"/>
        <description>The pciej_write function in hw/acpi_piix4.c in the PIIX4 Power Management emulation in qemu-kvm does not check if a device is hotpluggable before unplugging the PCI-ISA bridge, which allows privileged guest users to cause a denial of service (guest crash) and possibly execute arbitrary code by sending a crafted value to the 0xae08 (PCI_EJ_BASE) I/O port, which leads to a use-after-free related to "active qemu timers."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:48.969-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:02.726-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:21.437-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.160.el6" test_ref="oval:org.mitre.oval:tst:96982"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.160.el6" test_ref="oval:org.mitre.oval:tst:97967"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.160.el6" test_ref="oval:org.mitre.oval:tst:97842"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21920" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0506: rdesktop security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>rdesktop</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0506-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0506.html"/>
        <reference source="CVE" ref_id="CVE-2011-1595" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1595.html"/>
        <reference source="CESA-2011:0506" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-May/017557.html" ref_id="CESA-2011:0506-CentOS 5"/>
        <description>Directory traversal vulnerability in the disk_create function in disk.c in rdesktop before 1.7.0, when disk redirection is enabled, allows remote RDP servers to read or overwrite arbitrary files via a .. (dot dot) in a pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:56.057-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:02.464-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:21.040-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21920 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:24.338-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:19.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="rdesktop is earlier than 0:1.6.0-3.el5_6.2" test_ref="oval:org.mitre.oval:tst:137607"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="rdesktop is earlier than 0:1.6.0-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:97721"/>
            <criterion comment="rdesktop-debuginfo is earlier than 0:1.6.0-8.el6_0.1" test_ref="oval:org.mitre.oval:tst:137855"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21913" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0918: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0918-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0918.html"/>
        <reference source="CVE" ref_id="CVE-2011-2192" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2192.html"/>
        <reference source="CESA-2011:0918" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-July/017641.html" ref_id="CESA-2011:0918-CentOS 5"/>
        <description>The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:50.782-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:01.735-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:20.090-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21913 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:34.392-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:19.065-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl-devel is earlier than 0:7.15.5-9.el5_6.3" test_ref="oval:org.mitre.oval:tst:137150"/>
            <criterion comment="curl is earlier than 0:7.15.5-9.el5_6.3" test_ref="oval:org.mitre.oval:tst:137724"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="curl is earlier than 0:7.19.7-26.el6_1.1" test_ref="oval:org.mitre.oval:tst:97809"/>
            <criterion comment="curl-debuginfo is earlier than 0:7.19.7-26.el6_1.1" test_ref="oval:org.mitre.oval:tst:137578"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-26.el6_1.1" test_ref="oval:org.mitre.oval:tst:97421"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-26.el6_1.1" test_ref="oval:org.mitre.oval:tst:98175"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21911" version="185" class="patch">
      <metadata>
        <title>RHSA-2011:0164: mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0164-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0164.html"/>
        <reference source="CVE" ref_id="CVE-2010-3677" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3677.html"/>
        <reference source="CVE" ref_id="CVE-2010-3678" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3678.html"/>
        <reference source="CVE" ref_id="CVE-2010-3679" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3679.html"/>
        <reference source="CVE" ref_id="CVE-2010-3680" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3680.html"/>
        <reference source="CVE" ref_id="CVE-2010-3681" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3681.html"/>
        <reference source="CVE" ref_id="CVE-2010-3682" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3682.html"/>
        <reference source="CVE" ref_id="CVE-2010-3683" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3683.html"/>
        <reference source="CVE" ref_id="CVE-2010-3833" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3833.html"/>
        <reference source="CVE" ref_id="CVE-2010-3835" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3835.html"/>
        <reference source="CVE" ref_id="CVE-2010-3836" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3836.html"/>
        <reference source="CVE" ref_id="CVE-2010-3837" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3837.html"/>
        <reference source="CVE" ref_id="CVE-2010-3838" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3838.html"/>
        <reference source="CVE" ref_id="CVE-2010-3839" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3839.html"/>
        <reference source="CVE" ref_id="CVE-2010-3840" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3840.html"/>
        <description>The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling the PolyFromWKB function with Well-Known Binary (WKB) data containing a crafted number of (1) line strings or (2) line points.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:40.108-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:01.210-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:19.396-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97229"/>
          <criterion comment="mysql-server is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97081"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96839"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97124"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96978"/>
          <criterion comment="mysql-test is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96993"/>
          <criterion comment="mysql is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97142"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.52-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97218"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21910" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0390: rsync security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>rsync</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0390-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0390.html"/>
        <reference source="CVE" ref_id="CVE-2011-1097" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1097.html"/>
        <description>rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via malformed data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:11.118-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:01.140-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:19.311-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="rsync is earlier than 0:3.0.6-5.el6_0.1" test_ref="oval:org.mitre.oval:tst:97391"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21909" version="159" class="patch">
      <metadata>
        <title>RHSA-2011:0511: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0511-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0511.html"/>
        <reference source="CEBA" ref_id="CEBA-2011:0511"/>
        <reference source="CVE" ref_id="CVE-2011-0579" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0579.html"/>
        <reference source="CVE" ref_id="CVE-2011-0618" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0618.html"/>
        <reference source="CVE" ref_id="CVE-2011-0619" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0619.html"/>
        <reference source="CVE" ref_id="CVE-2011-0620" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0620.html"/>
        <reference source="CVE" ref_id="CVE-2011-0621" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0621.html"/>
        <reference source="CVE" ref_id="CVE-2011-0622" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0622.html"/>
        <reference source="CVE" ref_id="CVE-2011-0623" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0623.html"/>
        <reference source="CVE" ref_id="CVE-2011-0624" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0624.html"/>
        <reference source="CVE" ref_id="CVE-2011-0625" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0625.html"/>
        <reference source="CVE" ref_id="CVE-2011-0626" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0626.html"/>
        <reference source="CVE" ref_id="CVE-2011-0627" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0627.html"/>
        <reference source="CVE" ref_id="CVE-2011-0628" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0628.html"/>
        <description>Integer overflow in Adobe Flash Player before 10.3.181.14 on Windows, Mac OS X, Linux, and Solaris and before 10.3.185.21 on Android allows remote attackers to execute arbitrary code via ActionScript that improperly handles a long array object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:21.709-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.813-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:18.878-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="flash-plugin is earlier than 0:10.3.181.14-1.el5" test_ref="oval:org.mitre.oval:tst:97214"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.181.14-1.el6" test_ref="oval:org.mitre.oval:tst:97384"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21908" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0308: mailman security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>mailman</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0308-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0308.html"/>
        <reference source="CVE" ref_id="CVE-2010-3089" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3089.html"/>
        <reference source="CVE" ref_id="CVE-2011-0707" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0707.html"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:03.783-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.715-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:18.735-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="mailman is earlier than 3:2.1.12-14.el6_0.2" test_ref="oval:org.mitre.oval:tst:97101"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21906" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0376: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0376-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0376.html"/>
        <reference source="CESA" ref_id="CESA-2011:0376"/>
        <reference source="CVE" ref_id="CVE-2010-4352" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4352.html"/>
        <description>Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:57.289-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.531-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:18.499-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-devel is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:97463"/>
            <criterion comment="dbus is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:97598"/>
            <criterion comment="dbus-x11 is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:97339"/>
            <criterion comment="dbus-libs is earlier than 0:1.1.2-15.el5_6" test_ref="oval:org.mitre.oval:tst:97633"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-devel is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:97597"/>
            <criterion comment="dbus is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:97533"/>
            <criterion comment="dbus-x11 is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:97572"/>
            <criterion comment="dbus-libs is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:97366"/>
            <criterion comment="dbus-doc is earlier than 1:1.2.24-4.el6_0" test_ref="oval:org.mitre.oval:tst:96980"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21905" version="146" class="patch">
      <metadata>
        <title>RHSA-2011:0421: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0421-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0421.html"/>
        <reference source="CVE" ref_id="CVE-2010-3296" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3296.html"/>
        <reference source="CVE" ref_id="CVE-2010-4346" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4346.html"/>
        <reference source="CVE" ref_id="CVE-2010-4526" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4526.html"/>
        <reference source="CVE" ref_id="CVE-2010-4648" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4648.html"/>
        <reference source="CVE" ref_id="CVE-2010-4655" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4655.html"/>
        <reference source="CVE" ref_id="CVE-2010-4656" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4656.html"/>
        <reference source="CVE" ref_id="CVE-2011-0521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0521.html"/>
        <reference source="CVE" ref_id="CVE-2011-0695" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0695.html"/>
        <reference source="CVE" ref_id="CVE-2011-0710" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0710.html"/>
        <reference source="CVE" ref_id="CVE-2011-0716" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0716.html"/>
        <reference source="CVE" ref_id="CVE-2011-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1478.html"/>
        <description>The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure members, which might allow remote attackers to cause a denial of service (NULL pointer dereference) via a malformed VLAN frame.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:29.467-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.240-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:18.103-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97413"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97634"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97793"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97759"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97687"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97618"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97666"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97319"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97103"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97805"/>
          <criterion comment="kernel is earlier than 0:2.6.32-71.24.1.el6" test_ref="oval:org.mitre.oval:tst:97310"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21902" version="6" class="patch">
      <metadata>
        <title>RHSA-2014:0018: libXfont security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libXfont</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0018-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0018.html"/>
        <reference source="CESA" ref_id="CESA-2014:0018"/>
        <reference source="CVE" ref_id="CVE-2013-6462" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6462.html"/>
        <description>Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string in a character name in a BDF font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:58:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:42:31.548-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.143-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:17.954-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21902 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:37.127-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:41.396-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libXfont-devel is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:98673"/>
            <criterion comment="libXfont is earlier than 0:1.2.2-1.0.5.el5_10" test_ref="oval:org.mitre.oval:tst:98412"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libXfont-devel is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:99034"/>
            <criterion comment="libXfont is earlier than 0:1.4.5-3.el6_5" test_ref="oval:org.mitre.oval:tst:98834"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21901" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0392: libtiff security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0392-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0392.html"/>
        <reference source="CESA" ref_id="CESA-2011:0392"/>
        <reference source="CVE" ref_id="CVE-2011-1167" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1167.html"/>
        <description>Heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:50.298-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:04:00.046-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:17.811-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_6.7" test_ref="oval:org.mitre.oval:tst:97237"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_6.7" test_ref="oval:org.mitre.oval:tst:97664"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96686"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96834"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:97547"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21900" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0169: java-1.5.0-ibm security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0169-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0169.html"/>
        <reference source="CVE" ref_id="CVE-2010-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3553.html"/>
        <reference source="CVE" ref_id="CVE-2010-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3557.html"/>
        <reference source="CVE" ref_id="CVE-2010-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3571.html"/>
        <description>Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.  NOTE: the previous information was obtained from the October 2010 CPU.  Oracle has not commented on claims from a reliable researcher that this is an integer overflow in the color profile parser that allows remote attackers to execute arbitrary code via a crafted Tag structure in a color profile.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:27.146-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:59.895-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:17.632-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97095"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97146"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96896"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96911"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97121"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96913"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97213"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97204"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:96819"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:96918"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97086"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97172"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97247"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:97084"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:96683"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21899" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0843: postfix security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postfix</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0843-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0843.html"/>
        <reference source="CVE" ref_id="CVE-2011-1720" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1720.html"/>
        <reference source="CESA-2011:0843" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-May/017595.html" ref_id="CESA-2011:0843-CentOS 5"/>
        <description>The SMTP server in Postfix before 2.5.13, 2.6.x before 2.6.10, 2.7.x before 2.7.4, and 2.8.x before 2.8.3, when certain Cyrus SASL authentication methods are enabled, does not create a new server handle after client authentication fails, which allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) or possibly execute arbitrary code via an invalid AUTH command with one method followed by an AUTH command with a different method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:11.824-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:59.834-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:17.528-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21899 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:32.261-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:18.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postfix is earlier than 2:2.3.3-2.3.el5_6" test_ref="oval:org.mitre.oval:tst:136888"/>
            <criterion comment="postfix-pflogsumm is earlier than 2:2.3.3-2.3.el5_6" test_ref="oval:org.mitre.oval:tst:137246"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postfix is earlier than 2:2.6.6-2.2.el6_1" test_ref="oval:org.mitre.oval:tst:97716"/>
            <criterion comment="postfix-debuginfo is earlier than 2:2.6.6-2.2.el6_1" test_ref="oval:org.mitre.oval:tst:137547"/>
            <criterion comment="postfix-perl-scripts is earlier than 2:2.6.6-2.2.el6_1" test_ref="oval:org.mitre.oval:tst:97683"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21898" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0305: samba security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0305-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0305.html"/>
        <reference source="CVE" ref_id="CVE-2011-0719" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0719.html"/>
        <reference source="CESA-2011:0305" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017389.html" ref_id="CESA-2011:0305-CentOS 5"/>
        <description>Samba 3.x before 3.3.15, 3.4.x before 3.4.12, and 3.5.x before 3.5.7 does not perform range checks for file descriptors before use of the FD_SET macro, which allows remote attackers to cause a denial of service (stack memory corruption, and infinite loop or daemon crash) by opening a large number of files, related to (1) Winbind or (2) smbd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:07.959-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:59.749-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:17.413-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21898 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:22.833-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:18.350-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137684"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137852"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137854"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137175"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137757"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.29.el5_6.2" test_ref="oval:org.mitre.oval:tst:137782"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libsmbclient is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97558"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97294"/>
            <criterion comment="samba is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97333"/>
            <criterion comment="samba-client is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97466"/>
            <criterion comment="samba-common is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97255"/>
            <criterion comment="samba-debuginfo is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:137366"/>
            <criterion comment="samba-doc is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97568"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97488"/>
            <criterion comment="samba-swat is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97542"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97325"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97507"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.4-68.el6_0.2" test_ref="oval:org.mitre.oval:tst:97567"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21895" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0908: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0908-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0908.html"/>
        <reference source="CVE" ref_id="CVE-2010-3433" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3433.html"/>
        <description>The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:51.042-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:59.234-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:16.625-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postgresql is earlier than 0:8.4.5-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:99804"/>
          <criterion comment="postgresql-libs is earlier than 0:8.4.5-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:99482"/>
          <criterion comment="postgresql-server is earlier than 0:8.4.5-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:99469"/>
          <criterion comment="postgresql-devel is earlier than 0:8.4.5-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:99923"/>
          <criterion comment="postgresql-pltcl is earlier than 0:8.4.5-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:99851"/>
          <criterion comment="postgresql-plpython is earlier than 0:8.4.5-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:99974"/>
          <criterion comment="postgresql-docs is earlier than 0:8.4.5-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:99509"/>
          <criterion comment="postgresql-plperl is earlier than 0:8.4.5-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:99786"/>
          <criterion comment="postgresql-test is earlier than 0:8.4.5-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:99917"/>
          <criterion comment="postgresql-contrib is earlier than 0:8.4.5-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:99929"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21894" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1197: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1197-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1197.html"/>
        <reference source="CVE" ref_id="CVE-2011-2511" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2511.html"/>
        <description>Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:39.499-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:59.176-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:16.551-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.8.7-18.el6_1.1" test_ref="oval:org.mitre.oval:tst:97718"/>
          <criterion comment="libvirt-python is earlier than 0:0.8.7-18.el6_1.1" test_ref="oval:org.mitre.oval:tst:98109"/>
          <criterion comment="libvirt-client is earlier than 0:0.8.7-18.el6_1.1" test_ref="oval:org.mitre.oval:tst:97911"/>
          <criterion comment="libvirt is earlier than 0:0.8.7-18.el6_1.1" test_ref="oval:org.mitre.oval:tst:98258"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21892" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0560: sssd security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0560-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0560.html"/>
        <reference source="CVE" ref_id="CVE-2010-4341" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4341.html"/>
        <description>The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loop, crash, and login prevention) via a crafted packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:48.946-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:58.975-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:16.275-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="sssd-client is earlier than 0:1.5.1-34.el6" test_ref="oval:org.mitre.oval:tst:97714"/>
          <criterion comment="sssd is earlier than 0:1.5.1-34.el6" test_ref="oval:org.mitre.oval:tst:97748"/>
          <criterion comment="sssd-tools is earlier than 0:1.5.1-34.el6" test_ref="oval:org.mitre.oval:tst:97760"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21891" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0335: tomcat6 security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0335-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0335.html"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <reference source="CVE" ref_id="CVE-2011-0534" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0534.html"/>
        <description>Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:16.890-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:58.863-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:16.162-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:97321"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:97452"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:97312"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:97446"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:97573"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:96735"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:97291"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:97600"/>
          <criterion comment="tomcat6-log4j is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:97494"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-24.el6_0" test_ref="oval:org.mitre.oval:tst:97423"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21889" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1536: sos security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>sos</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1536-03" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1536.html"/>
        <reference source="CVE" ref_id="CVE-2011-4083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4083.html"/>
        <description>The sosreport utility in the Red Hat sos package before 1.7-9 and 2.x before 2.2-17 includes (1) Certificate-based Red Hat Network private entitlement keys and the (2) private key for the entitlement in an archive of debugging information, which might allow remote attackers to obtain sensitive information by reading the archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:47.802-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:58.599-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:15.894-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="sos is earlier than 0:2.2-17.el6" test_ref="oval:org.mitre.oval:tst:98681"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21887" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0345: qemu-kvm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0345-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0345.html"/>
        <reference source="CVE" ref_id="CVE-2011-0011" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0011.html"/>
        <description>qemu-kvm before 0.11.0 disables VNC authentication when the password is cleared, which allows remote attackers to bypass authentication and establish VNC sessions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:20.947-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:58.530-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:15.803-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.113.el6_0.8" test_ref="oval:org.mitre.oval:tst:96957"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.113.el6_0.8" test_ref="oval:org.mitre.oval:tst:97562"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.113.el6_0.8" test_ref="oval:org.mitre.oval:tst:97184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21884" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:1164: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1164-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1164.html"/>
        <reference source="CESA" ref_id="CESA-2011:1164"/>
        <reference source="CVE" ref_id="CVE-2011-0084" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0084.html"/>
        <reference source="CVE" ref_id="CVE-2011-2378" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2378.html"/>
        <reference source="CVE" ref_id="CVE-2011-2981" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2981.html"/>
        <reference source="CVE" ref_id="CVE-2011-2982" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2982.html"/>
        <reference source="CVE" ref_id="CVE-2011-2983" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2983.html"/>
        <reference source="CVE" ref_id="CVE-2011-2984" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2984.html"/>
        <description>Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:09.699-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:57.693-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:15.035-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el5" test_ref="oval:org.mitre.oval:tst:98356"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-2.el5" test_ref="oval:org.mitre.oval:tst:97400"/>
            <criterion comment="firefox is earlier than 0:3.6.20-2.el5" test_ref="oval:org.mitre.oval:tst:98011"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:98376"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:98396"/>
            <criterion comment="firefox is earlier than 0:3.6.20-2.el6_1" test_ref="oval:org.mitre.oval:tst:98239"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21881" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0910: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0910-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0910.html"/>
        <reference source="CVE" ref_id="CVE-2011-0188" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0188.html"/>
        <reference source="CVE" ref_id="CVE-2011-1004" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1004.html"/>
        <reference source="CVE" ref_id="CVE-2011-1005" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1005.html"/>
        <description>The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:08.734-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:57.562-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:14.879-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ruby is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:97909"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:98206"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:97368"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:98267"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:98260"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:98010"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:97884"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:97947"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.299-7.el6_1.1" test_ref="oval:org.mitre.oval:tst:98176"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21879" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1821: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1821-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1821.html"/>
        <reference source="CESA" ref_id="CESA-2011:1821"/>
        <reference source="CVE" ref_id="CVE-2011-4601" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4601.html"/>
        <reference source="CVE" ref_id="CVE-2011-4602" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4602.html"/>
        <description>The XMPP protocol plugin in libpurple in Pidgin before 2.10.1 does not properly handle missing fields in (1) voice-chat and (2) video-chat stanzas, which allows remote attackers to cause a denial of service (application crash) via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:54.420-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:57.422-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:14.735-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pidgin-perl is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:97926"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:98765"/>
          <criterion comment="pidgin-docs is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:98431"/>
          <criterion comment="libpurple is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:98279"/>
          <criterion comment="libpurple-perl is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:98787"/>
          <criterion comment="finch-devel is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:98809"/>
          <criterion comment="finch is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:98613"/>
          <criterion comment="libpurple-devel is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:98148"/>
          <criterion comment="pidgin-devel is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:98020"/>
          <criterion comment="pidgin is earlier than 0:2.7.9-3.el6.2" test_ref="oval:org.mitre.oval:tst:98883"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21875" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0586: libguestfs security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libguestfs</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0586-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0586.html"/>
        <reference source="CVE" ref_id="CVE-2010-3851" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3851.html"/>
        <description>libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files from the host via a crafted (1) qcow2, (2) VMDK, or (3) VDI header, related to lack of support for a disk format specifier.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:05.754-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:57.073-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:14.348-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libguestfs-java-devel is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97629"/>
          <criterion comment="libguestfs-java is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97274"/>
          <criterion comment="libguestfs-javadoc is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97973"/>
          <criterion comment="perl-Sys-Guestfs is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97823"/>
          <criterion comment="libguestfs is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97351"/>
          <criterion comment="ocaml-libguestfs is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97941"/>
          <criterion comment="libguestfs-mount is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97897"/>
          <criterion comment="python-libguestfs is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97726"/>
          <criterion comment="ocaml-libguestfs-devel is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97814"/>
          <criterion comment="libguestfs-devel is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97799"/>
          <criterion comment="libguestfs-tools-c is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97658"/>
          <criterion comment="ruby-libguestfs is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97950"/>
          <criterion comment="guestfish is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97698"/>
          <criterion comment="libguestfs-tools is earlier than 1:1.7.17-17.el6" test_ref="oval:org.mitre.oval:tst:97283"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21874" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0447: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0447-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0447.html"/>
        <reference source="CVE" ref_id="CVE-2011-0285" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0285.html"/>
        <description>The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted request that triggers an error condition.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:54.001-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:56.966-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:14.256-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:97493"/>
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:97526"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:97040"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:97670"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:97816"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:97126"/>
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.7" test_ref="oval:org.mitre.oval:tst:97843"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21872" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0464: kdelibs security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0464-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0464.html"/>
        <reference source="CVE" ref_id="CVE-2011-1094" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1094.html"/>
        <reference source="CVE" ref_id="CVE-2011-1168" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1168.html"/>
        <description>Cross-site scripting (XSS) vulnerability in the KHTMLPart::htmlError function in khtml/khtml_part.cpp in Konqueror in KDE SC 4.4.0 through 4.6.1 allows remote attackers to inject arbitrary web script or HTML via the URI in a URL corresponding to an unavailable web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:45.111-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:48.990-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:13.851-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kdelibs-apidocs is earlier than 6:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:97865"/>
          <criterion comment="kdelibs-common is earlier than 6:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:97795"/>
          <criterion comment="kdelibs-devel is earlier than 6:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:97485"/>
          <criterion comment="kdelibs is earlier than 6:4.3.4-11.el6_0.2" test_ref="oval:org.mitre.oval:tst:97537"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21871" version="55" class="patch">
      <metadata>
        <title>RHSA-2011:1083: fuse security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>fuse</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1083-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1083.html"/>
        <reference source="CVE" ref_id="CVE-2010-3879" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3879.html"/>
        <reference source="CVE" ref_id="CVE-2011-0541" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0541.html"/>
        <reference source="CVE" ref_id="CVE-2011-0542" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0542.html"/>
        <reference source="CVE" ref_id="CVE-2011-0543" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0543.html"/>
        <description>Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:15.591-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:48.831-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:13.688-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="fuse-devel is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:98291"/>
          <criterion comment="fuse-libs is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:98312"/>
          <criterion comment="fuse is earlier than 0:2.8.3-3.el6_1" test_ref="oval:org.mitre.oval:tst:97701"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21869" version="81" class="patch">
      <metadata>
        <title>RHSA-2011:0369: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0369-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0369.html"/>
        <reference source="CVE" ref_id="CVE-2011-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0444.html"/>
        <reference source="CVE" ref_id="CVE-2011-0538" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0538.html"/>
        <reference source="CVE" ref_id="CVE-2011-0713" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0713.html"/>
        <reference source="CVE" ref_id="CVE-2011-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1139.html"/>
        <reference source="CVE" ref_id="CVE-2011-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1140.html"/>
        <reference source="CVE" ref_id="CVE-2011-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1141.html"/>
        <description>epan/dissectors/packet-ldap.c in Wireshark 1.0.x, 1.2.0 through 1.2.14, and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (memory consumption) via (1) a long LDAP filter string or (2) an LDAP filter string containing many elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:17.457-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:48.621-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:13.498-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="wireshark is earlier than 0:1.2.15-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97656"/>
          <criterion comment="wireshark-devel is earlier than 0:1.2.15-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97596"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.2.15-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97021"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21868" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0558: perl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0558-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0558.html"/>
        <reference source="CVE" ref_id="CVE-2010-2761" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2761.html"/>
        <reference source="CVE" ref_id="CVE-2010-4410" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4410.html"/>
        <reference source="CVE" ref_id="CVE-2011-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1487.html"/>
        <description>The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not apply the taint attribute to the return value upon processing tainted input, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:06.858-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:48.415-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:13.259-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="perl-libs is earlier than 4:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:97336"/>
          <criterion comment="perl-core is earlier than 0:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:97899"/>
          <criterion comment="perl-Package-Constants is earlier than 1:0.02-119.el6" test_ref="oval:org.mitre.oval:tst:97699"/>
          <criterion comment="perl-suidperl is earlier than 4:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:97483"/>
          <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-119.el6" test_ref="oval:org.mitre.oval:tst:97920"/>
          <criterion comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-119.el6" test_ref="oval:org.mitre.oval:tst:97908"/>
          <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-119.el6" test_ref="oval:org.mitre.oval:tst:97936"/>
          <criterion comment="perl-Archive-Extract is earlier than 1:0.38-119.el6" test_ref="oval:org.mitre.oval:tst:97456"/>
          <criterion comment="perl-CGI is earlier than 0:3.51-119.el6" test_ref="oval:org.mitre.oval:tst:97327"/>
          <criterion comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-119.el6" test_ref="oval:org.mitre.oval:tst:97242"/>
          <criterion comment="perl-version is earlier than 3:0.77-119.el6" test_ref="oval:org.mitre.oval:tst:97923"/>
          <criterion comment="perl-Time-HiRes is earlier than 4:1.9721-119.el6" test_ref="oval:org.mitre.oval:tst:97429"/>
          <criterion comment="perl-Compress-Raw-Zlib is earlier than 0:2.023-119.el6" test_ref="oval:org.mitre.oval:tst:97853"/>
          <criterion comment="perl-Test-Simple is earlier than 0:0.92-119.el6" test_ref="oval:org.mitre.oval:tst:97739"/>
          <criterion comment="perl-Module-Loaded is earlier than 1:0.02-119.el6" test_ref="oval:org.mitre.oval:tst:97557"/>
          <criterion comment="perl-Module-Pluggable is earlier than 1:3.90-119.el6" test_ref="oval:org.mitre.oval:tst:97090"/>
          <criterion comment="perl-CPANPLUS is earlier than 0:0.88-119.el6" test_ref="oval:org.mitre.oval:tst:97846"/>
          <criterion comment="perl-parent is earlier than 1:0.221-119.el6" test_ref="oval:org.mitre.oval:tst:97599"/>
          <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-119.el6" test_ref="oval:org.mitre.oval:tst:97918"/>
          <criterion comment="perl-Pod-Escapes is earlier than 1:1.04-119.el6" test_ref="oval:org.mitre.oval:tst:97851"/>
          <criterion comment="perl-Test-Harness is earlier than 0:3.17-119.el6" test_ref="oval:org.mitre.oval:tst:97955"/>
          <criterion comment="perl-Pod-Simple is earlier than 1:3.13-119.el6" test_ref="oval:org.mitre.oval:tst:97691"/>
          <criterion comment="perl-Module-Load is earlier than 1:0.16-119.el6" test_ref="oval:org.mitre.oval:tst:97902"/>
          <criterion comment="perl-File-Fetch is earlier than 0:0.26-119.el6" test_ref="oval:org.mitre.oval:tst:97839"/>
          <criterion comment="perl-Module-CoreList is earlier than 0:2.18-119.el6" test_ref="oval:org.mitre.oval:tst:97887"/>
          <criterion comment="perl-IO-Zlib is earlier than 1:1.09-119.el6" test_ref="oval:org.mitre.oval:tst:97655"/>
          <criterion comment="perl-Params-Check is earlier than 1:0.26-119.el6" test_ref="oval:org.mitre.oval:tst:97490"/>
          <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-119.el6" test_ref="oval:org.mitre.oval:tst:97810"/>
          <criterion comment="perl is earlier than 4:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:97713"/>
          <criterion comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-119.el6" test_ref="oval:org.mitre.oval:tst:97668"/>
          <criterion comment="perl-devel is earlier than 4:5.10.1-119.el6" test_ref="oval:org.mitre.oval:tst:97863"/>
          <criterion comment="perl-Time-Piece is earlier than 0:1.15-119.el6" test_ref="oval:org.mitre.oval:tst:97798"/>
          <criterion comment="perl-Digest-SHA is earlier than 1:5.47-119.el6" test_ref="oval:org.mitre.oval:tst:97769"/>
          <criterion comment="perl-Archive-Tar is earlier than 0:1.58-119.el6" test_ref="oval:org.mitre.oval:tst:97636"/>
          <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-119.el6" test_ref="oval:org.mitre.oval:tst:97286"/>
          <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-119.el6" test_ref="oval:org.mitre.oval:tst:97812"/>
          <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-119.el6" test_ref="oval:org.mitre.oval:tst:97949"/>
          <criterion comment="perl-CPAN is earlier than 0:1.9402-119.el6" test_ref="oval:org.mitre.oval:tst:97931"/>
          <criterion comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-119.el6" test_ref="oval:org.mitre.oval:tst:97895"/>
          <criterion comment="perl-Term-UI is earlier than 0:0.20-119.el6" test_ref="oval:org.mitre.oval:tst:97889"/>
          <criterion comment="perl-Object-Accessor is earlier than 1:0.34-119.el6" test_ref="oval:org.mitre.oval:tst:97927"/>
          <criterion comment="perl-Module-Build is earlier than 1:0.3500-119.el6" test_ref="oval:org.mitre.oval:tst:97794"/>
          <criterion comment="perl-IPC-Cmd is earlier than 1:0.56-119.el6" test_ref="oval:org.mitre.oval:tst:97758"/>
          <criterion comment="perl-Log-Message is earlier than 1:0.02-119.el6" test_ref="oval:org.mitre.oval:tst:97956"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21860" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0779: avahi security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>avahi</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0779-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0779.html"/>
        <reference source="CVE" ref_id="CVE-2011-1002" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1002.html"/>
        <description>avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-2244.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:49.564-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:47.715-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:12.743-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="avahi-compat-howl-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97764"/>
          <criterion comment="avahi-gobject-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97802"/>
          <criterion comment="avahi-qt3-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97532"/>
          <criterion comment="avahi-ui is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97958"/>
          <criterion comment="avahi-qt4-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97637"/>
          <criterion comment="avahi-tools is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97684"/>
          <criterion comment="avahi-glib is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97982"/>
          <criterion comment="avahi-gobject is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97513"/>
          <criterion comment="avahi-compat-libdns_sd is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97520"/>
          <criterion comment="avahi-ui-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97638"/>
          <criterion comment="avahi-autoipd is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97894"/>
          <criterion comment="avahi-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97986"/>
          <criterion comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97934"/>
          <criterion comment="avahi-ui-tools is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:98021"/>
          <criterion comment="avahi-compat-howl is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97886"/>
          <criterion comment="avahi is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97872"/>
          <criterion comment="avahi-qt3 is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:98035"/>
          <criterion comment="avahi-glib-devel is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97997"/>
          <criterion comment="avahi-dnsconfd is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97845"/>
          <criterion comment="avahi-qt4 is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:97631"/>
          <criterion comment="avahi-libs is earlier than 0:0.6.25-11.el6" test_ref="oval:org.mitre.oval:tst:98075"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21859" version="250" class="patch">
      <metadata>
        <title>RHSA-2011:0282: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0282-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0282.html"/>
        <reference source="CVE" ref_id="CVE-2010-4422" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4422.html"/>
        <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html"/>
        <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html"/>
        <reference source="CVE" ref_id="CVE-2010-4450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4450.html"/>
        <reference source="CVE" ref_id="CVE-2010-4451" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4451.html"/>
        <reference source="CVE" ref_id="CVE-2010-4452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4452.html"/>
        <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html"/>
        <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html"/>
        <reference source="CVE" ref_id="CVE-2010-4463" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4463.html"/>
        <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html"/>
        <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html"/>
        <reference source="CVE" ref_id="CVE-2010-4467" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4467.html"/>
        <reference source="CVE" ref_id="CVE-2010-4468" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4468.html"/>
        <reference source="CVE" ref_id="CVE-2010-4469" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4469.html"/>
        <reference source="CVE" ref_id="CVE-2010-4470" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4470.html"/>
        <reference source="CVE" ref_id="CVE-2010-4471" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4471.html"/>
        <reference source="CVE" ref_id="CVE-2010-4472" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4472.html"/>
        <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html"/>
        <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:39.073-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:47.194-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:12.216-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97528"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96905"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97515"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97502"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97418"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97508"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97282"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97161"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97346"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97482"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97455"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97392"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21857" version="174" class="patch">
      <metadata>
        <title>RHSA-2011:0206: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0206-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0206.html"/>
        <reference source="CVE" ref_id="CVE-2011-0558" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0558.html"/>
        <reference source="CVE" ref_id="CVE-2011-0559" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0559.html"/>
        <reference source="CVE" ref_id="CVE-2011-0560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0560.html"/>
        <reference source="CVE" ref_id="CVE-2011-0561" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0561.html"/>
        <reference source="CVE" ref_id="CVE-2011-0571" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0571.html"/>
        <reference source="CVE" ref_id="CVE-2011-0572" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0572.html"/>
        <reference source="CVE" ref_id="CVE-2011-0573" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0573.html"/>
        <reference source="CVE" ref_id="CVE-2011-0574" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0574.html"/>
        <reference source="CVE" ref_id="CVE-2011-0575" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0575.html"/>
        <reference source="CVE" ref_id="CVE-2011-0577" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0577.html"/>
        <reference source="CVE" ref_id="CVE-2011-0578" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0578.html"/>
        <reference source="CVE" ref_id="CVE-2011-0607" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0607.html"/>
        <reference source="CVE" ref_id="CVE-2011-0608" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0608.html"/>
        <description>Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0578, and CVE-2011-0607.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:49.193-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.739-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.869-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21857 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:14.236-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:17.123-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.152.27-1.el5" test_ref="oval:org.mitre.oval:tst:137764"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.152.27-1.el6" test_ref="oval:org.mitre.oval:tst:97503"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21856" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0337: vsftpd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>vsftpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0337-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0337.html"/>
        <reference source="CVE" ref_id="CVE-2011-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0762.html"/>
        <reference source="CESA-2011:0337" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017401.html" ref_id="CESA-2011:0337-CentOS 5"/>
        <description>The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:16.639-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.661-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.779-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21856 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:23.068-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:16.825-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="vsftpd is earlier than 0:2.0.5-16.el5_6.1" test_ref="oval:org.mitre.oval:tst:137483"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="vsftpd is earlier than 0:2.2.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97416"/>
            <criterion comment="vsftpd-debuginfo is earlier than 0:2.2.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:137665"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21850" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0170: libuser security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libuser</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0170-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0170.html"/>
        <reference source="CESA" ref_id="CESA-2011:0170"/>
        <reference source="CVE" ref_id="CVE-2011-0002" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0002.html"/>
        <description>libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:22.827-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.558-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.681-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libuser-devel is earlier than 0:0.54.7-2.1.el5_5.2" test_ref="oval:org.mitre.oval:tst:97085"/>
            <criterion comment="libuser is earlier than 0:0.54.7-2.1.el5_5.2" test_ref="oval:org.mitre.oval:tst:96455"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libuser-devel is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:97036"/>
            <criterion comment="libuser is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:97221"/>
            <criterion comment="libuser-python is earlier than 0:0.56.13-4.el6_0.1" test_ref="oval:org.mitre.oval:tst:97120"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21848" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0862: nss security update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>nss</product>
          <product>nss-softokn</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0862-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0862.html"/>
        <reference source="CVE" ref_id="CVE-2010-3170" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3170.html"/>
        <description>Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:11.004-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.450-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.583-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nss-tools is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:99729"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:99513"/>
          <criterion comment="nss-sysinit is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:99557"/>
          <criterion comment="nss is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:99821"/>
          <criterion comment="nss-devel is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:99892"/>
          <criterion comment="nss-util is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:99731"/>
          <criterion comment="nss-util-devel is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:99609"/>
          <criterion comment="nss-softokn-devel is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:99709"/>
          <criterion comment="nss-softokn-freebl is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:99471"/>
          <criterion comment="nss-softokn is earlier than 0:3.12.8-1.el6_0" test_ref="oval:org.mitre.oval:tst:99772"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21847" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0332: scsi-target-utils security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <product>scsi-target-utils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0332-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0332.html"/>
        <reference source="CVE" ref_id="CVE-2011-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0001.html"/>
        <reference source="CESA-2011:0332" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017393.html" ref_id="CESA-2011:0332-CentOS 5"/>
        <description>Double free vulnerability in the iscsi_rx_handler function (usr/iscsi/iscsid.c) in the tgt daemon (tgtd) in Linux SCSI target framework (tgt) before 1.0.14, aka scsi-target-utils, allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown vectors related to a buffer overflow during iscsi login.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:23.168-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.378-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.502-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21847 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:24.935-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:16.547-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="scsi-target-utils is earlier than 0:1.0.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:96814"/>
            <criterion comment="scsi-target-utils-debuginfo is earlier than 0:1.0.4-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:137803"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="scsi-target-utils is earlier than 0:1.0.8-0.el5_6.1" test_ref="oval:org.mitre.oval:tst:137860"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21846" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1084: libsndfile security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libsndfile</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1084-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1084.html"/>
        <reference source="CVE" ref_id="CVE-2011-2696" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2696.html"/>
        <description>Integer overflow in libsndfile before 1.0.25 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio Format (PAF) file that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:20.800-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.305-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.255-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libsndfile is earlier than 0:1.0.20-3.el6_1.1" test_ref="oval:org.mitre.oval:tst:98151"/>
          <criterion comment="libsndfile-devel is earlier than 0:1.0.20-3.el6_1.1" test_ref="oval:org.mitre.oval:tst:97677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21842" version="52" class="patch">
      <metadata>
        <title>RHSA-2011:1241: ecryptfs-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>ecryptfs-utils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1241-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1241.html"/>
        <reference source="CESA" ref_id="CESA-2011:1241"/>
        <reference source="CVE" ref_id="CVE-2011-1831" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1831.html"/>
        <reference source="CVE" ref_id="CVE-2011-1832" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1832.html"/>
        <reference source="CVE" ref_id="CVE-2011-1834" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1834.html"/>
        <reference source="CVE" ref_id="CVE-2011-1835" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1835.html"/>
        <reference source="CVE" ref_id="CVE-2011-1837" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1837.html"/>
        <reference source="CVE" ref_id="CVE-2011-3145" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3145.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:38.464-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:46.099-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:11.009-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ecryptfs-utils-gui is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:97689"/>
            <criterion comment="ecryptfs-utils is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:98180"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:75-5.el5_7.2" test_ref="oval:org.mitre.oval:tst:98129"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ecryptfs-utils-python is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:98418"/>
            <criterion comment="ecryptfs-utils is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:97518"/>
            <criterion comment="ecryptfs-utils-devel is earlier than 0:82-6.el6_1.3" test_ref="oval:org.mitre.oval:tst:97673"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21822" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0324: logwatch security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>logwatch</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0324-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0324.html"/>
        <reference source="CVE" ref_id="CVE-2011-1018" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1018.html"/>
        <reference source="CESA-2011:0324" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017365.html" ref_id="CESA-2011:0324-CentOS 5"/>
        <description>logwatch.pl in Logwatch 7.3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in a log file name, as demonstrated via a crafted username to a Samba server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:02.872-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:45.442-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:10.336-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21822 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:14.464-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:16.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="logwatch is earlier than 0:7.3-9.el5_6" test_ref="oval:org.mitre.oval:tst:137653"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="logwatch is earlier than 0:7.3.6-49.el6" test_ref="oval:org.mitre.oval:tst:97039"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21821" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0391: libvirt security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0391-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0391.html"/>
        <reference source="CVE" ref_id="CVE-2011-1146" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1146.html"/>
        <reference source="CESA-2011:0391" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017456.html" ref_id="CESA-2011:0391-CentOS 5"/>
        <description>libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause a denial of service (host OS crash) or possibly execute arbitrary code via a (1) virNodeDeviceDettach, (2) virNodeDeviceReset, (3) virDomainRevertToSnapshot, (4) virDomainSnapshotDelete, (5) virNodeDeviceReAttach, or (6) virConnectDomainXMLToNative call, a different vulnerability than CVE-2008-5086.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:53.557-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:45.354-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:10.163-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21821 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:07.352-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:15.991-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvirt is earlier than 0:0.8.1-27.el6_0.5" test_ref="oval:org.mitre.oval:tst:96958"/>
            <criterion comment="libvirt-client is earlier than 0:0.8.1-27.el6_0.5" test_ref="oval:org.mitre.oval:tst:97630"/>
            <criterion comment="libvirt-debuginfo is earlier than 0:0.8.1-27.el6_0.5" test_ref="oval:org.mitre.oval:tst:137759"/>
            <criterion comment="libvirt-devel is earlier than 0:0.8.1-27.el6_0.5" test_ref="oval:org.mitre.oval:tst:97109"/>
            <criterion comment="libvirt-python is earlier than 0:0.8.1-27.el6_0.5" test_ref="oval:org.mitre.oval:tst:97647"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libvirt is earlier than 0:0.8.2-15.el5_6.3" test_ref="oval:org.mitre.oval:tst:136948"/>
            <criterion comment="libvirt-devel is earlier than 0:0.8.2-15.el5_6.3" test_ref="oval:org.mitre.oval:tst:137550"/>
            <criterion comment="libvirt-python is earlier than 0:0.8.2-15.el5_6.3" test_ref="oval:org.mitre.oval:tst:137859"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21813" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0154: hplip security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>hplip</product>
          <product>hplip3</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0154-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0154.html"/>
        <reference source="CVE" ref_id="CVE-2010-4267" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4267.html"/>
        <reference source="CESA-2011:0154" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017342.html" ref_id="CESA-2011:0154-CentOS 5"/>
        <description>Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:52.876-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:44.918-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:09.690-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21813 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:30.525-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:15.635-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="hpijs is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:137298"/>
            <criterion comment="hpijs3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:137888"/>
            <criterion comment="hplip is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:137564"/>
            <criterion comment="hplip3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:137308"/>
            <criterion comment="hplip3-common is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:136965"/>
            <criterion comment="hplip3-gui is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:137608"/>
            <criterion comment="hplip3-libs is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:137659"/>
            <criterion comment="libsane-hpaio is earlier than 0:1.6.7-6.el5_6.1" test_ref="oval:org.mitre.oval:tst:137858"/>
            <criterion comment="libsane-hpaio3 is earlier than 0:3.9.8-11.el5_6.1" test_ref="oval:org.mitre.oval:tst:137631"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="hpijs is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:96882"/>
            <criterion comment="hplip is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:96224"/>
            <criterion comment="hplip-common is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:96578"/>
            <criterion comment="hplip-debuginfo is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:137565"/>
            <criterion comment="hplip-gui is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:97154"/>
            <criterion comment="hplip-libs is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:97133"/>
            <criterion comment="libsane-hpaio is earlier than 0:3.9.8-33.el6_0.1" test_ref="oval:org.mitre.oval:tst:97130"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21812" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:1777: qemu-kvm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1777-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1777.html"/>
        <reference source="CESA" ref_id="CESA-2011:1777"/>
        <reference source="CVE" ref_id="CVE-2011-4111" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4111.html"/>
        <description>Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:24.349-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:44.835-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:09.593-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.209.el6_2.1" test_ref="oval:org.mitre.oval:tst:98344"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.209.el6_2.1" test_ref="oval:org.mitre.oval:tst:98881"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.209.el6_2.1" test_ref="oval:org.mitre.oval:tst:98906"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21809" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0291: java-1.5.0-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0291-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0291.html"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:53.700-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:44.728-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:09.474-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97468"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97268"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97487"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97201"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97560"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97385"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97432"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:97272"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97273"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97207"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97561"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97544"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97460"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:96815"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.3.el6" test_ref="oval:org.mitre.oval:tst:97361"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21792" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0423: postfix security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>postfix</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0423-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0423.html"/>
        <reference source="CVE" ref_id="CVE-2011-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0411.html"/>
        <description>The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:25.507-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:43.824-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:08.495-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="postfix-perl-scripts is earlier than 2:2.6.6-2.1.el6_0" test_ref="oval:org.mitre.oval:tst:97804"/>
          <criterion comment="postfix is earlier than 2:2.6.6-2.1.el6_0" test_ref="oval:org.mitre.oval:tst:97635"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21791" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1377: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1377-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1377.html"/>
        <reference source="CESA" ref_id="CESA-2011:1377"/>
        <reference source="CVE" ref_id="CVE-2011-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2483.html"/>
        <description>crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:03.572-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:43.725-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:08.374-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98070"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98409"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:97960"/>
            <criterion comment="postgresql-devel is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98583"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98369"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98422"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98593"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98172"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98231"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.23-1.el5_7.2" test_ref="oval:org.mitre.oval:tst:98173"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98538"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98349"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98004"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98411"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98566"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98607"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98510"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98655"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:97945"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.9-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98287"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21790" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0842: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0842-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0842.html"/>
        <reference source="CVE" ref_id="CVE-2011-1769" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1769.html"/>
        <reference source="CVE" ref_id="CVE-2011-1781" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1781.html"/>
        <description>SystemTap 1.4, when unprivileged (aka stapusr) mode is enabled, allows local users to cause a denial of service (divide-by-zero error and OOPS) via a crafted ELF program with DWARF expressions that are not properly handled by a stap script that performs stack unwinding (aka backtracing).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:36.760-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:43.617-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:08.215-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="systemtap-runtime is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:98090"/>
          <criterion comment="systemtap-client is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:98031"/>
          <criterion comment="systemtap-testsuite is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:97093"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:97867"/>
          <criterion comment="systemtap is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:97791"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:97770"/>
          <criterion comment="systemtap-grapher is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:97969"/>
          <criterion comment="systemtap-server is earlier than 0:1.4-6.el6_1.1" test_ref="oval:org.mitre.oval:tst:97747"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21789" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0356: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0356-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0356.html"/>
        <reference source="CVE" ref_id="CVE-2011-0284" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0284.html"/>
        <description>Double free vulnerability in the prepare_error_as function in do_as_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 through 1.9, when the PKINIT feature is enabled, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an e_data field containing typed data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:18.873-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:43.530-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:08.082-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:96892"/>
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:97541"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:97500"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:97622"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:97448"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:97404"/>
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.6" test_ref="oval:org.mitre.oval:tst:96627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21776" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1385: kdelibs and kdelibs3 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>kdelibs</product>
          <product>kdelibs3</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1385-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1385.html"/>
        <reference source="CESA" ref_id="CESA-2011:1385"/>
        <reference source="CVE" ref_id="CVE-2011-3365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3365.html"/>
        <description>The KDE SSL Wrapper (KSSL) API in KDE SC 4.6.0 through 4.7.1, and possibly earlier versions, does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:47.308-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:42.838-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:07.221-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:98337"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:98646"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-26.el5_7.1" test_ref="oval:org.mitre.oval:tst:97744"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="kdelibs3-apidocs is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:98739"/>
            <criterion comment="kdelibs3-devel is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:98386"/>
            <criterion comment="kdelibs3 is earlier than 0:3.5.10-24.el6_1.1" test_ref="oval:org.mitre.oval:tst:98274"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21772" version="146" class="patch">
      <metadata>
        <title>RHSA-2011:0886: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0886-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0886.html"/>
        <reference source="CVE" ref_id="CVE-2011-0083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0083.html"/>
        <reference source="CVE" ref_id="CVE-2011-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0085.html"/>
        <reference source="CVE" ref_id="CVE-2011-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2362.html"/>
        <reference source="CVE" ref_id="CVE-2011-2363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2363.html"/>
        <reference source="CVE" ref_id="CVE-2011-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2364.html"/>
        <reference source="CVE" ref_id="CVE-2011-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2365.html"/>
        <reference source="CVE" ref_id="CVE-2011-2374" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2374.html"/>
        <reference source="CVE" ref_id="CVE-2011-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2375.html"/>
        <reference source="CVE" ref_id="CVE-2011-2376" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2376.html"/>
        <reference source="CVE" ref_id="CVE-2011-2377" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2377.html"/>
        <reference source="CVE" ref_id="CVE-2011-2605" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2605.html"/>
        <description>CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:37.907-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:42.319-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:06.501-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.11-2.el6_1" test_ref="oval:org.mitre.oval:tst:98116"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21765" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:1437: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1437-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1437.html"/>
        <reference source="CESA" ref_id="CESA-2011:1437"/>
        <reference source="CVE" ref_id="CVE-2011-3647" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3647.html"/>
        <reference source="CVE" ref_id="CVE-2011-3648" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3648.html"/>
        <reference source="CVE" ref_id="CVE-2011-3650" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3650.html"/>
        <description>Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:37.563-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:41.955-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:05.868-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el5_7" test_ref="oval:org.mitre.oval:tst:98569"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.24-2.el5_7" test_ref="oval:org.mitre.oval:tst:98706"/>
            <criterion comment="firefox is earlier than 0:3.6.24-3.el5_7" test_ref="oval:org.mitre.oval:tst:98012"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98696"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.24-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:97782"/>
            <criterion comment="firefox is earlier than 0:3.6.24-3.el6_1" test_ref="oval:org.mitre.oval:tst:98533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21761" version="120" class="patch">
      <metadata>
        <title>RHSA-2011:1423: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1423-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1423.html"/>
        <reference source="CESA" ref_id="CESA-2011:1423"/>
        <reference source="CVE" ref_id="CVE-2011-0708" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0708.html"/>
        <reference source="CVE" ref_id="CVE-2011-1148" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1148.html"/>
        <reference source="CVE" ref_id="CVE-2011-1466" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1466.html"/>
        <reference source="CVE" ref_id="CVE-2011-1468" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1468.html"/>
        <reference source="CVE" ref_id="CVE-2011-1469" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1469.html"/>
        <reference source="CVE" ref_id="CVE-2011-1471" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1471.html"/>
        <reference source="CVE" ref_id="CVE-2011-1938" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1938.html"/>
        <reference source="CVE" ref_id="CVE-2011-2202" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2202.html"/>
        <reference source="CVE" ref_id="CVE-2011-2483" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2483.html"/>
        <description>crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it easier for context-dependent attackers to determine a cleartext password by leveraging knowledge of a password hash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:36.883-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:41.664-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:05.184-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98458"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98710"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98212"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98269"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98534"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:97907"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98687"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98415"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98016"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98635"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98477"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98716"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:97825"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98467"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98444"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98054"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98618"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98550"/>
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98358"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98744"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.3" test_ref="oval:org.mitre.oval:tst:98429"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98742"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98718"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98199"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98708"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98740"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98736"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98625"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:97750"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98512"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98433"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98684"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:97767"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98384"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98636"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98177"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98150"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98661"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98421"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98554"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98445"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98495"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98124"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:97790"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:97890"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98099"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98562"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21760" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0545: squid security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0545-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0545.html"/>
        <reference source="CVE" ref_id="CVE-2010-3072" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3072.html"/>
        <description>The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:58.909-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:41.608-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:05.021-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="squid is earlier than 7:3.1.10-1.el6" test_ref="oval:org.mitre.oval:tst:97435"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21758" version="200" class="patch">
      <metadata>
        <title>RHSA-2011:0471: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0471-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0471.html"/>
        <reference source="CVE" ref_id="CVE-2011-0065" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0065.html"/>
        <reference source="CVE" ref_id="CVE-2011-0066" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0066.html"/>
        <reference source="CVE" ref_id="CVE-2011-0067" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0067.html"/>
        <reference source="CVE" ref_id="CVE-2011-0069" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0069.html"/>
        <reference source="CVE" ref_id="CVE-2011-0070" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0070.html"/>
        <reference source="CVE" ref_id="CVE-2011-0071" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0071.html"/>
        <reference source="CVE" ref_id="CVE-2011-0072" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0072.html"/>
        <reference source="CVE" ref_id="CVE-2011-0073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0073.html"/>
        <reference source="CVE" ref_id="CVE-2011-0074" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0074.html"/>
        <reference source="CVE" ref_id="CVE-2011-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0075.html"/>
        <reference source="CVE" ref_id="CVE-2011-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0077.html"/>
        <reference source="CVE" ref_id="CVE-2011-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0078.html"/>
        <reference source="CVE" ref_id="CVE-2011-0080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0080.html"/>
        <reference source="CVE" ref_id="CVE-2011-0081" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0081.html"/>
        <reference source="CVE" ref_id="CVE-2011-1202" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1202.html"/>
        <reference source="CESA-2011:0471" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017460.html" ref_id="CESA-2011:0471-CentOS 5"/>
        <description>The xsltGenerateIdFunction function in functions.c in libxslt 1.1.26 and earlier, as used in Google Chrome before 10.0.648.127 and other products, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:18.715-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:41.314-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:04.438-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21758 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:29.826-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:14.293-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.17-3.el5_6" test_ref="oval:org.mitre.oval:tst:136898"/>
            <criterion comment="firefox is earlier than 0:3.6.17-1.el5_6" test_ref="oval:org.mitre.oval:tst:137877"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.17-3.el5_6" test_ref="oval:org.mitre.oval:tst:137813"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.6.17-1.el6_0" test_ref="oval:org.mitre.oval:tst:97875"/>
            <criterion comment="firefox-debuginfo is earlier than 0:3.6.17-1.el6_0" test_ref="oval:org.mitre.oval:tst:137359"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.17-4.el6_0" test_ref="oval:org.mitre.oval:tst:97757"/>
            <criterion comment="xulrunner-debuginfo is earlier than 0:1.9.2.17-4.el6_0" test_ref="oval:org.mitre.oval:tst:137795"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.17-4.el6_0" test_ref="oval:org.mitre.oval:tst:97834"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.6.17-1.el5.centos" test_ref="oval:org.mitre.oval:tst:137848"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.17-3.el5" test_ref="oval:org.mitre.oval:tst:137541"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.17-3.el5" test_ref="oval:org.mitre.oval:tst:137529"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21757" version="4" class="patch">
      <metadata>
        <title>RHSA-2010:0923: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0923-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0923.html"/>
        <reference source="CVE" ref_id="CVE-2010-3611" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3611.html"/>
        <description>ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6 packet containing a Relay-Forward message without an address in the Relay-Forward link-address field.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:24.224-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:41.255-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:02.125-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.1" test_ref="oval:org.mitre.oval:tst:99881"/>
          <criterion comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.1" test_ref="oval:org.mitre.oval:tst:100009"/>
          <criterion comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.1" test_ref="oval:org.mitre.oval:tst:99924"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21750" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0347: openldap security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0347-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0347.html"/>
        <reference source="CVE" ref_id="CVE-2011-1024" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1024.html"/>
        <reference source="CVE" ref_id="CVE-2011-1025" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1025.html"/>
        <reference source="CVE" ref_id="CVE-2011-1081" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1081.html"/>
        <description>modrdn.c in slapd in OpenLDAP 2.4.x before 2.4.24 allows remote attackers to cause a denial of service (daemon crash) via a relative Distinguished Name (DN) modification request (aka MODRDN operation) that contains an empty value for the OldDN field.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:09.155-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:41.083-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:01.633-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openldap-servers is earlier than 0:2.4.19-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:97431"/>
          <criterion comment="compat-openldap is earlier than 0:2.4.19_2.3.43-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:97426"/>
          <criterion comment="openldap is earlier than 0:2.4.19-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:97386"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.19-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:97328"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.19-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:97125"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.19-15.el6_0.2" test_ref="oval:org.mitre.oval:tst:96690"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21748" version="6" class="patch">
      <metadata>
        <title>RHSA-2014:0043: bind security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0043-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0043.html"/>
        <reference source="CESA" ref_id="CESA-2014:0043"/>
        <reference source="CVE" ref_id="CVE-2014-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0591.html"/>
        <description>The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a crafted DNS query to an authoritative nameserver that uses the NSEC3 signing feature.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-28T12:16:52">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-11T14:03:37.609-05:00">DRAFT</status_change>
            <status_change date="2014-03-03T04:01:01.900-05:00">INTERIM</status_change>
            <status_change date="2014-03-24T04:01:31.378-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21748 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:31:00.517-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:32:53.083-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:09.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:100083"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:99919"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:100304"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:100262"/>
          <criterion comment="bind is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:100041"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.23.rc1.el6_5.1" test_ref="oval:org.mitre.oval:tst:100282"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21745" version="68" class="patch">
      <metadata>
        <title>RHSA-2011:1221: samba and cifs-utils security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>cifs-utils</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1221-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1221.html"/>
        <reference source="CVE" ref_id="CVE-2011-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1678.html"/>
        <reference source="CVE" ref_id="CVE-2011-2522" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2522.html"/>
        <reference source="CVE" ref_id="CVE-2011-2694" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2694.html"/>
        <reference source="CVE" ref_id="CVE-2011-2724" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2724.html"/>
        <reference source="CVE" ref_id="CVE-2011-3585" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3585.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:00.119-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.842-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:00.880-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="cifs-utils is earlier than 0:4.8.1-2.el6_1.2" test_ref="oval:org.mitre.oval:tst:98341"/>
          <criterion comment="samba-client is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:97705"/>
          <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:98047"/>
          <criterion comment="samba is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:98414"/>
          <criterion comment="libsmbclient-devel is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:98428"/>
          <criterion comment="samba-common is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:98385"/>
          <criterion comment="samba-winbind is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:98306"/>
          <criterion comment="samba-doc is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:98323"/>
          <criterion comment="samba-winbind-devel is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:97874"/>
          <criterion comment="samba-winbind-clients is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:98084"/>
          <criterion comment="libsmbclient is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:98359"/>
          <criterion comment="samba-swat is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:98351"/>
          <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.6-86.el6_1.4" test_ref="oval:org.mitre.oval:tst:98121"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21742" version="146" class="patch">
      <metadata>
        <title>RHSA-2011:0860: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0860-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0860.html"/>
        <reference source="CVE" ref_id="CVE-2011-0802" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0802.html"/>
        <reference source="CVE" ref_id="CVE-2011-0814" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0814.html"/>
        <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-0863" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0863.html"/>
        <reference source="CVE" ref_id="CVE-2011-0864" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0864.html"/>
        <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html"/>
        <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html"/>
        <reference source="CVE" ref_id="CVE-2011-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0868.html"/>
        <reference source="CVE" ref_id="CVE-2011-0869" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0869.html"/>
        <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html"/>
        <reference source="CVE" ref_id="CVE-2011-0873" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0873.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, and 5.0 Update 29 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:41.687-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.514-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:02:00.109-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97917"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97961"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98145"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97755"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:98049"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97900"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97642"/>
            <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98013"/>
            <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97807"/>
            <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97990"/>
            <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:98038"/>
            <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97181"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21740" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0845: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>bind97</product>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0845-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0845.html"/>
        <reference source="CVE" ref_id="CVE-2011-1910" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1910.html"/>
        <reference source="CESA-2011:0845" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-May/017599.html" ref_id="CESA-2011:0845-CentOS 5"/>
        <description>Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:00.920-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.338-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:59.567-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21740 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:24.146-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:13.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind97 is earlier than 32:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:137605"/>
            <criterion comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:137688"/>
            <criterion comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:137801"/>
            <criterion comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:137715"/>
            <criterion comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_6.2" test_ref="oval:org.mitre.oval:tst:136906"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="bind is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:97847"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:98025"/>
            <criterion comment="bind-debuginfo is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:137885"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:97178"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:97153"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:98044"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P1.1" test_ref="oval:org.mitre.oval:tst:98017"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21737" version="29" class="patch">
      <metadata>
        <title>RHSA-2010:0945: quagga security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>quagga</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0945-01" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0945.html"/>
        <reference source="CVE" ref_id="CVE-2010-2948" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2948.html"/>
        <reference source="CVE" ref_id="CVE-2010-2949" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2949.html"/>
        <description>bgpd in Quagga before 0.99.17 does not properly parse AS paths, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unknown AS type in an AS path attribute in a BGP UPDATE message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:46:28.642-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:40.260-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:59.372-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="quagga-devel is earlier than 0:0.99.15-5.el6_0.1" test_ref="oval:org.mitre.oval:tst:100127"/>
          <criterion comment="quagga-contrib is earlier than 0:0.99.15-5.el6_0.1" test_ref="oval:org.mitre.oval:tst:100047"/>
          <criterion comment="quagga is earlier than 0:0.99.15-5.el6_0.1" test_ref="oval:org.mitre.oval:tst:100058"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21726" version="302" class="patch">
      <metadata>
        <title>RHSA-2011:0301: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0301-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0301.html"/>
        <reference source="CVE" ref_id="CVE-2011-0562" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0562.html"/>
        <reference source="CVE" ref_id="CVE-2011-0563" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0563.html"/>
        <reference source="CVE" ref_id="CVE-2011-0565" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0565.html"/>
        <reference source="CVE" ref_id="CVE-2011-0566" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0566.html"/>
        <reference source="CVE" ref_id="CVE-2011-0567" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0567.html"/>
        <reference source="CVE" ref_id="CVE-2011-0585" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0585.html"/>
        <reference source="CVE" ref_id="CVE-2011-0586" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0586.html"/>
        <reference source="CVE" ref_id="CVE-2011-0587" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0587.html"/>
        <reference source="CVE" ref_id="CVE-2011-0589" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0589.html"/>
        <reference source="CVE" ref_id="CVE-2011-0590" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0590.html"/>
        <reference source="CVE" ref_id="CVE-2011-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0591.html"/>
        <reference source="CVE" ref_id="CVE-2011-0592" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0592.html"/>
        <reference source="CVE" ref_id="CVE-2011-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0593.html"/>
        <reference source="CVE" ref_id="CVE-2011-0594" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0594.html"/>
        <reference source="CVE" ref_id="CVE-2011-0595" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0595.html"/>
        <reference source="CVE" ref_id="CVE-2011-0596" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0596.html"/>
        <reference source="CVE" ref_id="CVE-2011-0598" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0598.html"/>
        <reference source="CVE" ref_id="CVE-2011-0599" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0599.html"/>
        <reference source="CVE" ref_id="CVE-2011-0600" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0600.html"/>
        <reference source="CVE" ref_id="CVE-2011-0602" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0602.html"/>
        <reference source="CVE" ref_id="CVE-2011-0603" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0603.html"/>
        <reference source="CVE" ref_id="CVE-2011-0604" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0604.html"/>
        <reference source="CVE" ref_id="CVE-2011-0606" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0606.html"/>
        <description>Stack-based buffer overflow in rt3d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors related to a crafted length value, a different vulnerability than CVE-2011-0563 and CVE-2011-0589.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:12.818-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:39.628-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:58.530-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.2-1.el5" test_ref="oval:org.mitre.oval:tst:96576"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.2-1.el5" test_ref="oval:org.mitre.oval:tst:97249"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.2-3.el6_0" test_ref="oval:org.mitre.oval:tst:97437"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.2-3.el6_0" test_ref="oval:org.mitre.oval:tst:97545"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21719" version="406" class="patch">
      <metadata>
        <title>RHSA-2011:0007: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0007-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0007.html"/>
        <reference source="CVE" ref_id="CVE-2010-2492" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2492.html"/>
        <reference source="CVE" ref_id="CVE-2010-3067" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3067.html"/>
        <reference source="CVE" ref_id="CVE-2010-3078" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3078.html"/>
        <reference source="CVE" ref_id="CVE-2010-3080" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3080.html"/>
        <reference source="CVE" ref_id="CVE-2010-3298" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3298.html"/>
        <reference source="CVE" ref_id="CVE-2010-3477" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3477.html"/>
        <reference source="CVE" ref_id="CVE-2010-3861" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3861.html"/>
        <reference source="CVE" ref_id="CVE-2010-3865" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3865.html"/>
        <reference source="CVE" ref_id="CVE-2010-3874" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3874.html"/>
        <reference source="CVE" ref_id="CVE-2010-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3876.html"/>
        <reference source="CVE" ref_id="CVE-2010-3880" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3880.html"/>
        <reference source="CVE" ref_id="CVE-2010-4072" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4072.html"/>
        <reference source="CVE" ref_id="CVE-2010-4073" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4073.html"/>
        <reference source="CVE" ref_id="CVE-2010-4074" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4074.html"/>
        <reference source="CVE" ref_id="CVE-2010-4075" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4075.html"/>
        <reference source="CVE" ref_id="CVE-2010-4077" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4077.html"/>
        <reference source="CVE" ref_id="CVE-2010-4079" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4079.html"/>
        <reference source="CVE" ref_id="CVE-2010-4080" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4080.html"/>
        <reference source="CVE" ref_id="CVE-2010-4081" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4081.html"/>
        <reference source="CVE" ref_id="CVE-2010-4082" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4082.html"/>
        <reference source="CVE" ref_id="CVE-2010-4083" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4083.html"/>
        <reference source="CVE" ref_id="CVE-2010-4158" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4158.html"/>
        <reference source="CVE" ref_id="CVE-2010-4160" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4160.html"/>
        <reference source="CVE" ref_id="CVE-2010-4162" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4162.html"/>
        <reference source="CVE" ref_id="CVE-2010-4163" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4163.html"/>
        <reference source="CVE" ref_id="CVE-2010-4242" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4242.html"/>
        <reference source="CVE" ref_id="CVE-2010-4248" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4248.html"/>
        <reference source="CVE" ref_id="CVE-2010-4249" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4249.html"/>
        <reference source="CVE" ref_id="CVE-2010-4263" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4263.html"/>
        <reference source="CVE" ref_id="CVE-2010-4525" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4525.html"/>
        <reference source="CVE" ref_id="CVE-2010-4668" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4668.html"/>
        <description>The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.37-rc7 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device, related to an unaligned map.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4163.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:32.502-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:38.812-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:57.558-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96226"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96254"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96943"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96786"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96945"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96763"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96890"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96069"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96562"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96748"/>
          <criterion comment="kernel is earlier than 0:2.6.32-71.14.1.el6" test_ref="oval:org.mitre.oval:tst:96749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21718" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1356: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1356-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1356.html"/>
        <reference source="CVE" ref_id="CVE-2011-3380" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3380.html"/>
        <description>Openswan 2.6.29 through 2.6.35 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto IKE daemon crash) via an ISAKMP message with an invalid KEY_LENGTH attribute, which is not properly handled by the error handling function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:11.416-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:38.755-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:57.461-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openswan is earlier than 0:2.6.32-4.el6_1.2" test_ref="oval:org.mitre.oval:tst:98488"/>
          <criterion comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.2" test_ref="oval:org.mitre.oval:tst:98438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21713" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0214: java-1.6.0-openjdk security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0214-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0214.html"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <reference source="CESA-2011:0214" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017311.html" ref_id="CESA-2011:0214-CentOS 5"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:26.903-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:38.337-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:56.882-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21713 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:26.820-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:13.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.18.b17.el5" test_ref="oval:org.mitre.oval:tst:137875"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.18.b17.el5" test_ref="oval:org.mitre.oval:tst:137610"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.18.b17.el5" test_ref="oval:org.mitre.oval:tst:137775"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.18.b17.el5" test_ref="oval:org.mitre.oval:tst:137575"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.18.b17.el5" test_ref="oval:org.mitre.oval:tst:137751"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97461"/>
            <criterion comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:137857"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97143"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97316"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97445"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.36.b17.el6_0" test_ref="oval:org.mitre.oval:tst:97379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21712" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0428: dhcp security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0428-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0428.html"/>
        <reference source="CVE" ref_id="CVE-2011-0997" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0997.html"/>
        <reference source="CESA-2011:0428" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017295.html" ref_id="CESA-2011:0428-CentOS 5"/>
        <description>dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:12.343-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:38.277-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:56.804-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21712 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:23.375-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:13.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dhcp is earlier than 12:3.0.5-23.el5_6.4" test_ref="oval:org.mitre.oval:tst:137712"/>
            <criterion comment="dhcp-devel is earlier than 12:3.0.5-23.el5_6.4" test_ref="oval:org.mitre.oval:tst:137895"/>
            <criterion comment="libdhcp4client-devel is earlier than 12:3.0.5-23.el5_6.4" test_ref="oval:org.mitre.oval:tst:137676"/>
            <criterion comment="dhclient is earlier than 12:3.0.5-23.el5_6.4" test_ref="oval:org.mitre.oval:tst:137671"/>
            <criterion comment="libdhcp4client is earlier than 12:3.0.5-23.el5_6.4" test_ref="oval:org.mitre.oval:tst:137734"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:97534"/>
            <criterion comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:97866"/>
            <criterion comment="dhcp-debuginfo is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:137889"/>
            <criterion comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.4" test_ref="oval:org.mitre.oval:tst:97717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21707" version="55" class="patch">
      <metadata>
        <title>RHSA-2014:0133: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0133-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0133.html"/>
        <reference source="CESA" ref_id="CESA-2014:0133"/>
        <reference source="CVE" ref_id="CVE-2014-1477" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1477.html"/>
        <reference source="CVE" ref_id="CVE-2014-1479" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1479.html"/>
        <reference source="CVE" ref_id="CVE-2014-1481" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1481.html"/>
        <reference source="CVE" ref_id="CVE-2014-1482" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1482.html"/>
        <reference source="CVE" ref_id="CVE-2014-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1486.html"/>
        <reference source="CVE" ref_id="CVE-2014-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-1487.html"/>
        <description>The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-02-14T11:55:48">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-02-19T08:08:15.974-05:00">DRAFT</status_change>
            <status_change date="2014-03-10T04:00:35.023-04:00">INTERIM</status_change>
            <status_change date="2014-03-31T04:00:11.697-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21707 - CentOS was added to RedHat vulnerabilities and products were added were nessesary." date="2014-04-23T10:34:00.988-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-04-23T10:36:15.711-04:00">INTERIM</status_change>
            <status_change date="2014-05-12T04:00:09.096-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21707 - RHEL/CentOS  patches with added CESA ids" date="2014-06-20T11:49:00.014-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-20T11:51:39.703-04:00">INTERIM</status_change>
            <status_change date="2014-07-07T04:00:52.145-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:100278"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:24.3.0-2.el6_5" test_ref="oval:org.mitre.oval:tst:100038"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:113897"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.3" test_ref="oval:org.mitre.oval:tst:113478"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21701" version="120" class="patch">
      <metadata>
        <title>RHSA-2011:0475: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0475-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0475.html"/>
        <reference source="CVE" ref_id="CVE-2011-0070" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0070.html"/>
        <reference source="CVE" ref_id="CVE-2011-0071" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0071.html"/>
        <reference source="CVE" ref_id="CVE-2011-0073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0073.html"/>
        <reference source="CVE" ref_id="CVE-2011-0074" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0074.html"/>
        <reference source="CVE" ref_id="CVE-2011-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0075.html"/>
        <reference source="CVE" ref_id="CVE-2011-0077" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0077.html"/>
        <reference source="CVE" ref_id="CVE-2011-0078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0078.html"/>
        <reference source="CVE" ref_id="CVE-2011-0080" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0080.html"/>
        <reference source="CVE" ref_id="CVE-2011-0081" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0081.html"/>
        <description>Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.17 and 4.x before 4.0.1, and Thunderbird 3.1.x before 3.1.10, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:24.575-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:37.914-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:56.426-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.10-1.el6_0" test_ref="oval:org.mitre.oval:tst:97811"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21698" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0258: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0258-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0258.html"/>
        <reference source="CVE" ref_id="CVE-2010-3315" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3315.html"/>
        <reference source="CVE" ref_id="CVE-2010-4539" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4539.html"/>
        <reference source="CVE" ref_id="CVE-2010-4644" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4644.html"/>
        <description>Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:29.856-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:37.657-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:56.025-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:97480"/>
          <criterion comment="subversion-kde is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:96994"/>
          <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:97376"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:96988"/>
          <criterion comment="subversion-devel is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:97535"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:97505"/>
          <criterion comment="subversion-gnome is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:97144"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:97517"/>
          <criterion comment="subversion is earlier than 0:1.6.11-2.el6_0.2" test_ref="oval:org.mitre.oval:tst:97501"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21697" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0451: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0451-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0451.html"/>
        <reference source="CVE" ref_id="CVE-2011-0611" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0611.html"/>
        <description>Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Windows, Adobe Reader 9.x before 9.4.4 and 10.x before 10.0.3 on Mac OS X, and Adobe Acrobat 9.x before 9.4.4 and 10.x before 10.0.3 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content; as demonstrated by a Microsoft Office document with an embedded .swf file that has a size inconsistency in a "group of included constants," object type confusion, ActionScript that adds custom functions to prototypes, and Date objects; and as exploited in the wild in April 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:58.461-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:37.591-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:55.913-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.2.159.1-1.el5" test_ref="oval:org.mitre.oval:tst:97697"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.2.159.1-1.el6" test_ref="oval:org.mitre.oval:tst:97749"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21695" version="172" class="patch">
      <metadata>
        <title>RHSA-2010:0842: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2010:0842-02" ref_url="https://rhn.redhat.com/errata/RHSA-2010-0842.html"/>
        <reference source="CVE" ref_id="CVE-2010-2803" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2803.html"/>
        <reference source="CVE" ref_id="CVE-2010-2955" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2955.html"/>
        <reference source="CVE" ref_id="CVE-2010-2962" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2962.html"/>
        <reference source="CVE" ref_id="CVE-2010-3079" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3079.html"/>
        <reference source="CVE" ref_id="CVE-2010-3081" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3081.html"/>
        <reference source="CVE" ref_id="CVE-2010-3084" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3084.html"/>
        <reference source="CVE" ref_id="CVE-2010-3301" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3301.html"/>
        <reference source="CVE" ref_id="CVE-2010-3432" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3432.html"/>
        <reference source="CVE" ref_id="CVE-2010-3437" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3437.html"/>
        <reference source="CVE" ref_id="CVE-2010-3442" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3442.html"/>
        <reference source="CVE" ref_id="CVE-2010-3698" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3698.html"/>
        <reference source="CVE" ref_id="CVE-2010-3705" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3705.html"/>
        <reference source="CVE" ref_id="CVE-2010-3904" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3904.html"/>
        <description>The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:48:40">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:45:12.045-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:37.320-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:55.518-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99610"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99799"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99585"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99322"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99441"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99769"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99874"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99822"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99891"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99597"/>
          <criterion comment="kernel is earlier than 0:2.6.32-71.7.1.el6" test_ref="oval:org.mitre.oval:tst:99053"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21686" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1289: librsvg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>librsvg2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1289-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1289.html"/>
        <reference source="CVE" ref_id="CVE-2011-3146" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3146.html"/>
        <description>librsvg before 2.34.1 uses the node name to identify the type of node, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference) and possibly execute arbitrary code via a SVG file with a node with the element name starting with "fe," which is misidentified as a RsvgFilterPrimitive.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:00.268-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:36.535-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:54.495-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="librsvg2-devel is earlier than 0:2.26.0-5.el6_1.1" test_ref="oval:org.mitre.oval:tst:98503"/>
          <criterion comment="librsvg2 is earlier than 0:2.26.0-5.el6_1.1" test_ref="oval:org.mitre.oval:tst:98216"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21684" version="7" class="patch">
      <metadata>
        <title>RHSA-2011:0472: nss security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0472-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0472.html"/>
        <reference source="CESA-2011:0472" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017458.html" ref_id="CESA-2011:0472-CentOS 5"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the development of security-enabled client and server applications.

This erratum blacklists a small number of HTTPS certificates by adding
them, flagged as untrusted, to the NSS Builtin Object Token (the
libnssckbi.so library) certificate store. (BZ#689430)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not blacklist the certificates for applications that use the
NSS library, but do not use the NSS Builtin Object Token (such as curl).

All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:13.426-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:36.486-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:54.392-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21684 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:37.778-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:41.100-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21684 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:08.517-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:12.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss-devel is earlier than 0:3.12.8-4.el5_6" test_ref="oval:org.mitre.oval:tst:136908"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.8-4.el5_6" test_ref="oval:org.mitre.oval:tst:137680"/>
            <criterion comment="nss is earlier than 0:3.12.8-4.el5_6" test_ref="oval:org.mitre.oval:tst:137879"/>
            <criterion comment="nss-tools is earlier than 0:3.12.8-4.el5_6" test_ref="oval:org.mitre.oval:tst:137837"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="nss is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:97681"/>
            <criterion comment="nss-debuginfo is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:137770"/>
            <criterion comment="nss-devel is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:97411"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:97578"/>
            <criterion comment="nss-sysinit is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:97712"/>
            <criterion comment="nss-tools is earlier than 0:3.12.8-3.el6_0" test_ref="oval:org.mitre.oval:tst:97833"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21671" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0455: polkit security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>polkit</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0455-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0455.html"/>
        <reference source="CVE" ref_id="CVE-2011-1485" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1485.html"/>
        <description>Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:24.882-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:36.022-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:53.730-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="polkit is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:97317"/>
          <criterion comment="polkit-desktop-policy is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:97700"/>
          <criterion comment="polkit-docs is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:97601"/>
          <criterion comment="polkit-devel is earlier than 0:0.96-2.el6_0.1" test_ref="oval:org.mitre.oval:tst:97640"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21665" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1512: libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1512-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1512.html"/>
        <reference source="CESA" ref_id="CESA-2012:1512"/>
        <reference source="CVE" ref_id="CVE-2012-5134" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5134.html"/>
        <description>Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:39.254-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:35.934-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:53.594-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:94612"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:94428"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.6" test_ref="oval:org.mitre.oval:tst:94892"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:94867"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:94379"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:94940"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.4" test_ref="oval:org.mitre.oval:tst:94495"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21660" version="96" class="patch">
      <metadata>
        <title>RHSA-2012:1431: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1431-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1431.html"/>
        <reference source="CVE" ref_id="CVE-2012-5274" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5274.html"/>
        <reference source="CVE" ref_id="CVE-2012-5275" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5275.html"/>
        <reference source="CVE" ref_id="CVE-2012-5276" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5276.html"/>
        <reference source="CVE" ref_id="CVE-2012-5277" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5277.html"/>
        <reference source="CVE" ref_id="CVE-2012-5278" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5278.html"/>
        <reference source="CVE" ref_id="CVE-2012-5279" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5279.html"/>
        <reference source="CVE" ref_id="CVE-2012-5280" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5280.html"/>
        <description>Buffer overflow in Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux, before 11.1.111.24 on Android 2.x and 3.x, and before 11.1.115.27 on Android 4.x; Adobe AIR before 3.5.0.600; and Adobe AIR SDK before 3.5.0.600 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, and CVE-2012-5277.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:54.611-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:35.657-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:53.166-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21660 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:05.625-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:12.079-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.251-1.el5" test_ref="oval:org.mitre.oval:tst:137431"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.251-1.el6" test_ref="oval:org.mitre.oval:tst:94647"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21659" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1349: rpm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>rpm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1349-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1349.html"/>
        <reference source="CESA" ref_id="CESA-2011:1349"/>
        <reference source="CVE" ref_id="CVE-2011-3378" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3378.html"/>
        <description>RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via an rpm package with crafted headers and offsets that are not properly handled when a package is queried or installed, related to (1) the regionSwab function, (2) the headerLoad function, and (3) multiple functions in rpmio/rpmpgp.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:08.097-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:35.559-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:53.010-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="rpm is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98600"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98576"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98316"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98481"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98499"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98577"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-22.el5_7.2" test_ref="oval:org.mitre.oval:tst:98357"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="rpm-cron is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98449"/>
            <criterion comment="rpm is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98544"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98501"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98154"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98400"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:97971"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-16.el6_1.1" test_ref="oval:org.mitre.oval:tst:98377"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21649" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1409: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1409-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1409.html"/>
        <reference source="CVE" ref_id="CVE-2011-3207" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3207.html"/>
        <description>crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:35.560-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:35.491-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:52.902-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl-devel is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:98304"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:98651"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:98389"/>
          <criterion comment="openssl is earlier than 0:1.0.0-10.el6_1.5" test_ref="oval:org.mitre.oval:tst:98586"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21647" version="198" class="patch">
      <metadata>
        <title>RHSA-2011:0542: Red Hat Enterprise Linux 6.1 kernel security, bug fix and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0542-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0542.html"/>
        <reference source="CVE" ref_id="CVE-2010-3881" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3881.html"/>
        <reference source="CVE" ref_id="CVE-2010-4251" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4251.html"/>
        <reference source="CVE" ref_id="CVE-2010-4805" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4805.html"/>
        <reference source="CVE" ref_id="CVE-2011-0999" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0999.html"/>
        <reference source="CVE" ref_id="CVE-2011-1010" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1010.html"/>
        <reference source="CVE" ref_id="CVE-2011-1023" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1023.html"/>
        <reference source="CVE" ref_id="CVE-2011-1082" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1082.html"/>
        <reference source="CVE" ref_id="CVE-2011-1090" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1090.html"/>
        <reference source="CVE" ref_id="CVE-2011-1163" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1163.html"/>
        <reference source="CVE" ref_id="CVE-2011-1170" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1170.html"/>
        <reference source="CVE" ref_id="CVE-2011-1171" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1171.html"/>
        <reference source="CVE" ref_id="CVE-2011-1172" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1172.html"/>
        <reference source="CVE" ref_id="CVE-2011-1494" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1494.html"/>
        <reference source="CVE" ref_id="CVE-2011-1495" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1495.html"/>
        <reference source="CVE" ref_id="CVE-2011-1581" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1581.html"/>
        <description>The bond_select_queue function in drivers/net/bonding/bond_main.c in the Linux kernel before 2.6.39, when a network device with a large number of receive queues is installed but the default tx_queues setting is used, does not properly restrict queue indexes, which allows remote attackers to cause a denial of service (BUG and system crash) or possibly have unspecified other impact by sending network traffic.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:56.643-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:34.780-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:52.226-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97892"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97612"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97981"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97912"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97772"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97896"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97735"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97779"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97893"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97970"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.0.15.el6" test_ref="oval:org.mitre.oval:tst:97925"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21643" version="211" class="patch">
      <metadata>
        <title>RHSA-2012:1462: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1462-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1462.html"/>
        <reference source="CESA" ref_id="CESA-2012:1462"/>
        <reference source="CVE" ref_id="CVE-2012-0540" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0540.html"/>
        <reference source="CVE" ref_id="CVE-2012-1688" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1688.html"/>
        <reference source="CVE" ref_id="CVE-2012-1689" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1689.html"/>
        <reference source="CVE" ref_id="CVE-2012-1690" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1690.html"/>
        <reference source="CVE" ref_id="CVE-2012-1703" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1703.html"/>
        <reference source="CVE" ref_id="CVE-2012-1734" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1734.html"/>
        <reference source="CVE" ref_id="CVE-2012-2749" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2749.html"/>
        <reference source="CVE" ref_id="CVE-2012-3150" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3150.html"/>
        <reference source="CVE" ref_id="CVE-2012-3158" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3158.html"/>
        <reference source="CVE" ref_id="CVE-2012-3160" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3160.html"/>
        <reference source="CVE" ref_id="CVE-2012-3163" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3163.html"/>
        <reference source="CVE" ref_id="CVE-2012-3166" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3166.html"/>
        <reference source="CVE" ref_id="CVE-2012-3167" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3167.html"/>
        <reference source="CVE" ref_id="CVE-2012-3173" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3173.html"/>
        <reference source="CVE" ref_id="CVE-2012-3177" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3177.html"/>
        <reference source="CVE" ref_id="CVE-2012-3180" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3180.html"/>
        <reference source="CVE" ref_id="CVE-2012-3197" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3197.html"/>
        <description>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Replication.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:09.037-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:34.345-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:51.662-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:94903"/>
          <criterion comment="mysql-server is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:94483"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:94813"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:94908"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:94395"/>
          <criterion comment="mysql-test is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:94794"/>
          <criterion comment="mysql is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:94388"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.66-1.el6_3" test_ref="oval:org.mitre.oval:tst:93930"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21641" version="159" class="patch">
      <metadata>
        <title>RHSA-2011:1465: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1465-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1465.html"/>
        <reference source="CVE" ref_id="CVE-2011-1162" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1162.html"/>
        <reference source="CVE" ref_id="CVE-2011-1577" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1577.html"/>
        <reference source="CVE" ref_id="CVE-2011-2494" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2494.html"/>
        <reference source="CVE" ref_id="CVE-2011-2699" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2699.html"/>
        <reference source="CVE" ref_id="CVE-2011-2905" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2905.html"/>
        <reference source="CVE" ref_id="CVE-2011-3188" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3188.html"/>
        <reference source="CVE" ref_id="CVE-2011-3191" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3191.html"/>
        <reference source="CVE" ref_id="CVE-2011-3353" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3353.html"/>
        <reference source="CVE" ref_id="CVE-2011-3359" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3359.html"/>
        <reference source="CVE" ref_id="CVE-2011-3363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3363.html"/>
        <reference source="CVE" ref_id="CVE-2011-3593" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3593.html"/>
        <reference source="CVE" ref_id="CVE-2011-4326" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4326.html"/>
        <description>The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:04.925-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:34.009-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:51.286-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98774"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98193"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98610"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98612"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98749"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98753"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98496"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98378"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98457"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98511"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.21.1.el6" test_ref="oval:org.mitre.oval:tst:98758"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21640" version="187" class="patch">
      <metadata>
        <title>RHSA-2014:0026: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2014:0026-00" ref_url="https://rhn.redhat.com/errata/RHSA-2014-0026.html"/>
        <reference source="CESA" ref_id="CESA-2014:0026"/>
        <reference source="CVE" ref_id="CVE-2013-5878" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5878.html"/>
        <reference source="CVE" ref_id="CVE-2013-5884" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5884.html"/>
        <reference source="CVE" ref_id="CVE-2013-5893" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5893.html"/>
        <reference source="CVE" ref_id="CVE-2013-5896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5896.html"/>
        <reference source="CVE" ref_id="CVE-2013-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5907.html"/>
        <reference source="CVE" ref_id="CVE-2013-5910" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5910.html"/>
        <reference source="CVE" ref_id="CVE-2014-0368" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0368.html"/>
        <reference source="CVE" ref_id="CVE-2014-0373" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0373.html"/>
        <reference source="CVE" ref_id="CVE-2014-0376" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0376.html"/>
        <reference source="CVE" ref_id="CVE-2014-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0411.html"/>
        <reference source="CVE" ref_id="CVE-2014-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0416.html"/>
        <reference source="CVE" ref_id="CVE-2014-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0422.html"/>
        <reference source="CVE" ref_id="CVE-2014-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0423.html"/>
        <reference source="CVE" ref_id="CVE-2014-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2014-0428.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to "insufficient security checks in IIOP streams," which allows attackers to escape the sandbox.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:58:59">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:42:30.941-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:25.367-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:50.968-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21640 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:37.627-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:40.179-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.51-2.4.4.1.el6_5" test_ref="oval:org.mitre.oval:tst:98951"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.51-2.4.4.1.el6_5" test_ref="oval:org.mitre.oval:tst:98990"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.51-2.4.4.1.el6_5" test_ref="oval:org.mitre.oval:tst:98599"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.51-2.4.4.1.el6_5" test_ref="oval:org.mitre.oval:tst:98892"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.51-2.4.4.1.el6_5" test_ref="oval:org.mitre.oval:tst:98705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21637" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1807: jasper security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>jasper</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1807-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1807.html"/>
        <reference source="CESA" ref_id="CESA-2011:1807"/>
        <reference source="CVE" ref_id="CVE-2011-4516" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4516.html"/>
        <reference source="CVE" ref_id="CVE-2011-4517" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4517.html"/>
        <description>The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:45.532-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:25.089-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:50.668-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="jasper is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:98372"/>
          <criterion comment="jasper-utils is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:98766"/>
          <criterion comment="jasper-devel is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:98796"/>
          <criterion comment="jasper-libs is earlier than 0:1.900.1-15.el6_1.1" test_ref="oval:org.mitre.oval:tst:98671"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21632" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1455: gegl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>gegl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1455-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1455.html"/>
        <reference source="CESA" ref_id="CESA-2012:1455"/>
        <reference source="CVE" ref_id="CVE-2012-4433" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4433.html"/>
        <description>Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a large (1) width or (2) height value in a Portable Pixel Map (ppm) image, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:37.792-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:25.019-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:50.576-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gegl-devel is earlier than 0:0.1.2-4.el6_3" test_ref="oval:org.mitre.oval:tst:94887"/>
          <criterion comment="gegl is earlier than 0:0.1.2-4.el6_3" test_ref="oval:org.mitre.oval:tst:94672"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21631" version="146" class="patch">
      <metadata>
        <title>RHSA-2011:1445: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1445-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1445.html"/>
        <reference source="CVE" ref_id="CVE-2011-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2445.html"/>
        <reference source="CVE" ref_id="CVE-2011-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2450.html"/>
        <reference source="CVE" ref_id="CVE-2011-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2451.html"/>
        <reference source="CVE" ref_id="CVE-2011-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2452.html"/>
        <reference source="CVE" ref_id="CVE-2011-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2453.html"/>
        <reference source="CVE" ref_id="CVE-2011-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2454.html"/>
        <reference source="CVE" ref_id="CVE-2011-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2455.html"/>
        <reference source="CVE" ref_id="CVE-2011-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2456.html"/>
        <reference source="CVE" ref_id="CVE-2011-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2457.html"/>
        <reference source="CVE" ref_id="CVE-2011-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2459.html"/>
        <reference source="CVE" ref_id="CVE-2011-2460" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2460.html"/>
        <description>Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454, CVE-2011-2455, and CVE-2011-2459.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:39.608-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:24.778-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:50.281-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.11-1.el5" test_ref="oval:org.mitre.oval:tst:98483"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.11-1.el6" test_ref="oval:org.mitre.oval:tst:98326"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21630" version="198" class="patch">
      <metadata>
        <title>RHSA-2012:1483: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1483-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1483.html"/>
        <reference source="CESA" ref_id="CESA-2012:1483"/>
        <reference source="CVE" ref_id="CVE-2012-4201" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4201.html"/>
        <reference source="CVE" ref_id="CVE-2012-4202" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4202.html"/>
        <reference source="CVE" ref_id="CVE-2012-4207" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4207.html"/>
        <reference source="CVE" ref_id="CVE-2012-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4209.html"/>
        <reference source="CVE" ref_id="CVE-2012-4214" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4214.html"/>
        <reference source="CVE" ref_id="CVE-2012-4215" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4215.html"/>
        <reference source="CVE" ref_id="CVE-2012-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4216.html"/>
        <reference source="CVE" ref_id="CVE-2012-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5829.html"/>
        <reference source="CVE" ref_id="CVE-2012-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5830.html"/>
        <reference source="CVE" ref_id="CVE-2012-5833" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5833.html"/>
        <reference source="CVE" ref_id="CVE-2012-5835" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5835.html"/>
        <reference source="CVE" ref_id="CVE-2012-5839" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5839.html"/>
        <reference source="CVE" ref_id="CVE-2012-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5840.html"/>
        <reference source="CVE" ref_id="CVE-2012-5841" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5841.html"/>
        <reference source="CVE" ref_id="CVE-2012-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5842.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:29.671-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:23.984-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:49.851-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:94901"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94413"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:94939"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.11-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94864"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21627" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0318: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0318-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0318.html"/>
        <reference source="CVE" ref_id="CVE-2011-0192" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0192.html"/>
        <reference source="CESA-2011:0318" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017361.html" ref_id="CESA-2011:0318-CentOS 5"/>
        <description>Buffer overflow in Fax4Decode in LibTIFF 3.9.4 and possibly other versions, as used in ImageIO in Apple iTunes before 10.2 on Windows and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding, related to the EXPAND2D macro in libtiff/tif_fax3.h.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:18.344-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:23.854-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:49.626-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21627 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:15.792-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:11.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-7.el5_6.6" test_ref="oval:org.mitre.oval:tst:137374"/>
            <criterion comment="libtiff is earlier than 0:3.8.2-7.el5_6.6" test_ref="oval:org.mitre.oval:tst:137251"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="libtiff is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96582"/>
            <criterion comment="libtiff-debuginfo is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:137522"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97364"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97569"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21626" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0554: python security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>python</product>
          <product>python-docs</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0554-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0554.html"/>
        <reference source="CVE" ref_id="CVE-2010-3493" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3493.html"/>
        <reference source="CVE" ref_id="CVE-2011-1015" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1015.html"/>
        <reference source="CVE" ref_id="CVE-2011-1521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1521.html"/>
        <description>The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:04.192-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:23.742-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:49.460-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="python-docs is earlier than 0:2.6.6-2.el6" test_ref="oval:org.mitre.oval:tst:97840"/>
          <criterion comment="python-devel is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:97975"/>
          <criterion comment="python-test is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:97957"/>
          <criterion comment="tkinter is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:97773"/>
          <criterion comment="python is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:97659"/>
          <criterion comment="python-libs is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:97978"/>
          <criterion comment="python-tools is earlier than 0:2.6.6-20.el6" test_ref="oval:org.mitre.oval:tst:97952"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21625" version="107" class="patch">
      <metadata>
        <title>RHSA-2011:0183: openoffice.org security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0183-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0183.html"/>
        <reference source="CVE" ref_id="CVE-2010-3450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3450.html"/>
        <reference source="CVE" ref_id="CVE-2010-3451" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3451.html"/>
        <reference source="CVE" ref_id="CVE-2010-3452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3452.html"/>
        <reference source="CVE" ref_id="CVE-2010-3453" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3453.html"/>
        <reference source="CVE" ref_id="CVE-2010-3454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3454.html"/>
        <reference source="CVE" ref_id="CVE-2010-3689" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3689.html"/>
        <reference source="CVE" ref_id="CVE-2010-4253" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4253.html"/>
        <reference source="CVE" ref_id="CVE-2010-4643" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4643.html"/>
        <description>Heap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Truevision TGA (TARGA) file in an ODF or Microsoft Office document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:42.587-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:23.339-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:48.877-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97307"/>
          <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97236"/>
          <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96639"/>
          <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97281"/>
          <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96848"/>
          <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97194"/>
          <criterion comment="autocorr-af is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96687"/>
          <criterion comment="openoffice.org-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97108"/>
          <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97151"/>
          <criterion comment="openoffice.org-langpack-dz is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97175"/>
          <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97171"/>
          <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97216"/>
          <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97064"/>
          <criterion comment="broffice.org-brand is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97230"/>
          <criterion comment="autocorr-vi is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97292"/>
          <criterion comment="openoffice.org-langpack-uk is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97174"/>
          <criterion comment="autocorr-ja is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96936"/>
          <criterion comment="openoffice.org-testtools is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97225"/>
          <criterion comment="openoffice.org-langpack-es is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96970"/>
          <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96991"/>
          <criterion comment="openoffice.org-calc is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97223"/>
          <criterion comment="openoffice.org-opensymbol-fonts is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97239"/>
          <criterion comment="autocorr-eu is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97248"/>
          <criterion comment="openoffice.org is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96864"/>
          <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97106"/>
          <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97179"/>
          <criterion comment="openoffice.org-presentation-minimizer is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96795"/>
          <criterion comment="autocorr-sl is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97287"/>
          <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96779"/>
          <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97188"/>
          <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97100"/>
          <criterion comment="openoffice.org-calc-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97052"/>
          <criterion comment="openoffice.org-draw is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97185"/>
          <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96586"/>
          <criterion comment="openoffice.org-devel is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96249"/>
          <criterion comment="autocorr-ga is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96291"/>
          <criterion comment="openoffice.org-report-builder is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97208"/>
          <criterion comment="autocorr-mn is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96987"/>
          <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97107"/>
          <criterion comment="broffice.org-math is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97001"/>
          <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96446"/>
          <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96326"/>
          <criterion comment="autocorr-pl is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97191"/>
          <criterion comment="openoffice.org-langpack-de is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96620"/>
          <criterion comment="openoffice.org-base-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97119"/>
          <criterion comment="broffice.org-writer is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97044"/>
          <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97193"/>
          <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96843"/>
          <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97048"/>
          <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97267"/>
          <criterion comment="openoffice.org-brand is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97094"/>
          <criterion comment="broffice.org-impress is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96534"/>
          <criterion comment="autocorr-da is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97117"/>
          <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97228"/>
          <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97091"/>
          <criterion comment="openoffice.org-langpack-pa is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96724"/>
          <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96960"/>
          <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97275"/>
          <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97131"/>
          <criterion comment="openoffice.org-writer is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96314"/>
          <criterion comment="broffice.org-calc is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97190"/>
          <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97077"/>
          <criterion comment="autocorr-tr is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97118"/>
          <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97263"/>
          <criterion comment="autocorr-sv is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96938"/>
          <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97007"/>
          <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97187"/>
          <criterion comment="autocorr-fr is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96798"/>
          <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97150"/>
          <criterion comment="openoffice.org-langpack-it is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96974"/>
          <criterion comment="autocorr-es is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97051"/>
          <criterion comment="openoffice.org-langpack-en is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96618"/>
          <criterion comment="openoffice.org-langpack-ro is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97301"/>
          <criterion comment="autocorr-fi is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96425"/>
          <criterion comment="openoffice.org-impress is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96330"/>
          <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97295"/>
          <criterion comment="openoffice.org-javafilter is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96823"/>
          <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97293"/>
          <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97245"/>
          <criterion comment="openoffice.org-langpack-mai_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96412"/>
          <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97252"/>
          <criterion comment="openoffice.org-wiki-publisher is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97113"/>
          <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96338"/>
          <criterion comment="autocorr-de is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97096"/>
          <criterion comment="broffice.org-base is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97129"/>
          <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97165"/>
          <criterion comment="openoffice.org-math is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97046"/>
          <criterion comment="autocorr-nl is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96977"/>
          <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97189"/>
          <criterion comment="openoffice.org-draw-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97089"/>
          <criterion comment="openoffice.org-pyuno is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97206"/>
          <criterion comment="autocorr-bg is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97302"/>
          <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97123"/>
          <criterion comment="openoffice.org-bsh is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96907"/>
          <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96880"/>
          <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96350"/>
          <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97067"/>
          <criterion comment="openoffice.org-langpack-sr is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97232"/>
          <criterion comment="openoffice.org-math-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97152"/>
          <criterion comment="autocorr-ru is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97233"/>
          <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97024"/>
          <criterion comment="autocorr-en is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97102"/>
          <criterion comment="autocorr-sk is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96392"/>
          <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96551"/>
          <criterion comment="openoffice.org-sdk is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96449"/>
          <criterion comment="autocorr-pt is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96660"/>
          <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97195"/>
          <criterion comment="openoffice.org-writer-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97262"/>
          <criterion comment="autocorr-lt is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97145"/>
          <criterion comment="autocorr-cs is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96656"/>
          <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97013"/>
          <criterion comment="openoffice.org-rhino is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97226"/>
          <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97304"/>
          <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97055"/>
          <criterion comment="openoffice.org-presenter-screen is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96808"/>
          <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96861"/>
          <criterion comment="openoffice.org-impress-core is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96817"/>
          <criterion comment="autocorr-fa is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97168"/>
          <criterion comment="broffice.org-draw is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97005"/>
          <criterion comment="openoffice.org-pdfimport is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96871"/>
          <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97203"/>
          <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97314"/>
          <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96929"/>
          <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97313"/>
          <criterion comment="autocorr-zh is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96565"/>
          <criterion comment="autocorr-ko is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96538"/>
          <criterion comment="openoffice.org-headless is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96937"/>
          <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97110"/>
          <criterion comment="autocorr-it is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97246"/>
          <criterion comment="openoffice.org-ogltrans is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97033"/>
          <criterion comment="openoffice.org-base is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96972"/>
          <criterion comment="autocorr-hu is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97132"/>
          <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97349"/>
          <criterion comment="autocorr-lb is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:97182"/>
          <criterion comment="openoffice.org-ure is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96870"/>
          <criterion comment="openoffice.org-emailmerge is earlier than 1:3.2.1-19.6.el6_0.5" test_ref="oval:org.mitre.oval:tst:96812"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21622" version="172" class="patch">
      <metadata>
        <title>RHSA-2011:0357: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0357-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0357.html"/>
        <reference source="CVE" ref_id="CVE-2010-4422" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4422.html"/>
        <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html"/>
        <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html"/>
        <reference source="CVE" ref_id="CVE-2010-4452" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4452.html"/>
        <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html"/>
        <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html"/>
        <reference source="CVE" ref_id="CVE-2010-4463" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4463.html"/>
        <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html"/>
        <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html"/>
        <reference source="CVE" ref_id="CVE-2010-4467" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4467.html"/>
        <reference source="CVE" ref_id="CVE-2010-4468" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4468.html"/>
        <reference source="CVE" ref_id="CVE-2010-4471" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4471.html"/>
        <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html"/>
        <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:24.401-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:22.968-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:48.394-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97115"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97412"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97496"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97570"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97522"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97271"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97465"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97331"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:96645"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97586"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97566"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97177"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:96949"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97474"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97227"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21620" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:1439: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1439-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1439.html"/>
        <reference source="CVE" ref_id="CVE-2011-3647" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3647.html"/>
        <reference source="CVE" ref_id="CVE-2011-3648" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3648.html"/>
        <reference source="CVE" ref_id="CVE-2011-3650" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3650.html"/>
        <description>Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:09.568-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:22.876-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:48.245-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.16-2.el6_1" test_ref="oval:org.mitre.oval:tst:98480"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21616" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0859: cyrus-imapd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>cyrus-imapd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0859-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0859.html"/>
        <reference source="CVE" ref_id="CVE-2011-1926" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1926.html"/>
        <reference source="CESA-2011:0859" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-June/017612.html" ref_id="CESA-2011:0859-CentOS 5"/>
        <description>The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:20.143-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:22.725-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:47.784-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21616 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:22.093-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:11.290-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cyrus-imapd is earlier than 0:2.3.7-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137794"/>
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137312"/>
            <criterion comment="cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137725"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137863"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98076"/>
            <criterion comment="cyrus-imapd-debuginfo is earlier than 0:2.3.16-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:137763"/>
            <criterion comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98096"/>
            <criterion comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98120"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21614" version="200" class="patch">
      <metadata>
        <title>RHSA-2012:1465: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1465-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1465.html"/>
        <reference source="CVE" ref_id="CVE-2012-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1531.html"/>
        <reference source="CVE" ref_id="CVE-2012-3143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3143.html"/>
        <reference source="CVE" ref_id="CVE-2012-3216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3216.html"/>
        <reference source="CVE" ref_id="CVE-2012-4820" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4820.html"/>
        <reference source="CVE" ref_id="CVE-2012-4822" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4822.html"/>
        <reference source="CVE" ref_id="CVE-2012-5069" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5069.html"/>
        <reference source="CVE" ref_id="CVE-2012-5071" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5071.html"/>
        <reference source="CVE" ref_id="CVE-2012-5073" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5073.html"/>
        <reference source="CVE" ref_id="CVE-2012-5075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5075.html"/>
        <reference source="CVE" ref_id="CVE-2012-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5079.html"/>
        <reference source="CVE" ref_id="CVE-2012-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5081.html"/>
        <reference source="CVE" ref_id="CVE-2012-5083" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5083.html"/>
        <reference source="CVE" ref_id="CVE-2012-5084" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5084.html"/>
        <reference source="CVE" ref_id="CVE-2012-5089" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5089.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "IIOP type reuse management" in ObjectStreamClass.java.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:40.970-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:22.428-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:47.549-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21614 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:08.227-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:09.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137182"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137815"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:136914"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137245"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137914"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:136920"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137765"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137560"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94301"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94843"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94718"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94732"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94795"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94316"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94711"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21608" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1088: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1088-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1088.html"/>
        <reference source="CVE" ref_id="CVE-2011-2502" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2502.html"/>
        <reference source="CVE" ref_id="CVE-2011-2503" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2503.html"/>
        <description>The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local users to gain privileges via a race condition between the signature validation and the module initialization.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:13.258-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:22.342-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:47.424-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="systemtap-runtime is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:97360"/>
          <criterion comment="systemtap-client is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98233"/>
          <criterion comment="systemtap-testsuite is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98072"/>
          <criterion comment="systemtap-sdt-devel is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:97679"/>
          <criterion comment="systemtap is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98192"/>
          <criterion comment="systemtap-initscript is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98131"/>
          <criterion comment="systemtap-grapher is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98294"/>
          <criterion comment="systemtap-server is earlier than 0:1.4-6.el6_1.2" test_ref="oval:org.mitre.oval:tst:98346"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21607" version="172" class="patch">
      <metadata>
        <title>RHSA-2012:1289: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1289-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1289.html"/>
        <reference source="CVE" ref_id="CVE-2012-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0547.html"/>
        <reference source="CVE" ref_id="CVE-2012-0551" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0551.html"/>
        <reference source="CVE" ref_id="CVE-2012-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1682.html"/>
        <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
        <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
        <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
        <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
        <reference source="CVE" ref_id="CVE-2012-1721" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1721.html"/>
        <reference source="CVE" ref_id="CVE-2012-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1722.html"/>
        <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
        <reference source="CVE" ref_id="CVE-2012-1726" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1726.html"/>
        <reference source="CVE" ref_id="CVE-2012-3136" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3136.html"/>
        <reference source="CVE" ref_id="CVE-2012-4681" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4681.html"/>
        <description>Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:48.817-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:22.053-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:47.198-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94350"/>
          <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94729"/>
          <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94723"/>
          <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94698"/>
          <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94067"/>
          <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94725"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21604" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1256: ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1256.html"/>
        <reference source="CESA" ref_id="CESA-2012:1256"/>
        <reference source="CVE" ref_id="CVE-2012-4405" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4405.html"/>
        <description>Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow.  NOTE: this issue is also described as an array index error.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:19.288-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:21.960-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:47.067-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:94323"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:94481"/>
            <criterion comment="ghostscript is earlier than 0:8.70-14.el5_8.1" test_ref="oval:org.mitre.oval:tst:94158"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:94529"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:93565"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:94516"/>
            <criterion comment="ghostscript is earlier than 0:8.70-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:93913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21603" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:1180: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1180-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1180.html"/>
        <reference source="CESA" ref_id="CESA-2012:1180"/>
        <reference source="CVE" ref_id="CVE-2011-2896" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2896.html"/>
        <reference source="CVE" ref_id="CVE-2012-3403" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3403.html"/>
        <reference source="CVE" ref_id="CVE-2012-3481" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3481.html"/>
        <description>Integer overflow in the ReadImage function in plug-ins/common/file-gif-load.c in the GIF image format plug-in in GIMP 2.8.x and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted height and len properties in a GIF image file, which triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:01.178-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:21.847-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:46.916-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gimp-libs is earlier than 2:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:94429"/>
          <criterion comment="gimp-devel is earlier than 2:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:94110"/>
          <criterion comment="gimp-help-browser is earlier than 2:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:93814"/>
          <criterion comment="gimp is earlier than 2:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:94327"/>
          <criterion comment="gimp-devel-tools is earlier than 2:2.6.9-4.el6_3.3" test_ref="oval:org.mitre.oval:tst:94182"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21602" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0568: eclipse security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>eclipse</product>
          <product>eclipse-birt</product>
          <product>eclipse-callgraph</product>
          <product>eclipse-cdt</product>
          <product>eclipse-changelog</product>
          <product>eclipse-dtp</product>
          <product>eclipse-emf</product>
          <product>eclipse-gef</product>
          <product>eclipse-linuxprofilingframework</product>
          <product>eclipse-mylyn</product>
          <product>eclipse-oprofile</product>
          <product>eclipse-rse</product>
          <product>eclipse-valgrind</product>
          <product>icu4j</product>
          <product>jetty-eclipse</product>
          <product>objectweb-asm</product>
          <product>sat4j</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0568-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0568.html"/>
        <reference source="CVE" ref_id="CVE-2010-4647" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4647.html"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:18.073-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:21.628-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:46.666-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="jetty-eclipse is earlier than 0:6.1.24-2.el6" test_ref="oval:org.mitre.oval:tst:97932"/>
          <criterion comment="eclipse-rse is earlier than 0:3.2-1.el6" test_ref="oval:org.mitre.oval:tst:97800"/>
          <criterion comment="sat4j is earlier than 0:2.2.0-4.0.el6" test_ref="oval:org.mitre.oval:tst:97662"/>
          <criterion comment="objectweb-asm is earlier than 0:3.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:97754"/>
          <criterion comment="objectweb-asm-javadoc is earlier than 0:3.2-2.1.el6" test_ref="oval:org.mitre.oval:tst:97729"/>
          <criterion comment="eclipse-emf-xsd-sdk is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:97983"/>
          <criterion comment="eclipse-emf is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:97711"/>
          <criterion comment="eclipse-emf-sdk is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:97603"/>
          <criterion comment="eclipse-emf-examples is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:97906"/>
          <criterion comment="eclipse-emf-xsd is earlier than 0:2.6.0-1.el6" test_ref="oval:org.mitre.oval:tst:97922"/>
          <criterion comment="eclipse-dtp is earlier than 0:1.8.1-1.1.el6" test_ref="oval:org.mitre.oval:tst:97350"/>
          <criterion comment="eclipse-birt is earlier than 0:2.6.0-1.1.el6" test_ref="oval:org.mitre.oval:tst:97620"/>
          <criterion comment="eclipse-linuxprofilingframework is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:97202"/>
          <criterion comment="eclipse-callgraph is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:97944"/>
          <criterion comment="eclipse-changelog is earlier than 1:2.7.0-1.el6" test_ref="oval:org.mitre.oval:tst:97951"/>
          <criterion comment="eclipse-valgrind is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:97980"/>
          <criterion comment="eclipse-oprofile is earlier than 0:0.6.1-1.el6" test_ref="oval:org.mitre.oval:tst:97883"/>
          <criterion comment="icu4j-javadoc is earlier than 1:4.2.1-5.el6" test_ref="oval:org.mitre.oval:tst:97877"/>
          <criterion comment="icu4j-eclipse is earlier than 1:4.2.1-5.el6" test_ref="oval:org.mitre.oval:tst:97484"/>
          <criterion comment="icu4j is earlier than 1:4.2.1-5.el6" test_ref="oval:org.mitre.oval:tst:97663"/>
          <criterion comment="eclipse-gef-sdk is earlier than 0:3.6.1-3.el6" test_ref="oval:org.mitre.oval:tst:97860"/>
          <criterion comment="eclipse-gef-examples is earlier than 0:3.6.1-3.el6" test_ref="oval:org.mitre.oval:tst:97318"/>
          <criterion comment="eclipse-gef is earlier than 0:3.6.1-3.el6" test_ref="oval:org.mitre.oval:tst:97614"/>
          <criterion comment="eclipse is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:97733"/>
          <criterion comment="eclipse-platform is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:97606"/>
          <criterion comment="eclipse-jdt is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:97458"/>
          <criterion comment="eclipse-pde is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:97442"/>
          <criterion comment="eclipse-swt is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:97940"/>
          <criterion comment="eclipse-rcp is earlier than 1:3.6.1-6.13.el6" test_ref="oval:org.mitre.oval:tst:97661"/>
          <criterion comment="eclipse-mylyn-pde is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:97491"/>
          <criterion comment="eclipse-mylyn-java is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:97966"/>
          <criterion comment="eclipse-mylyn is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:97878"/>
          <criterion comment="eclipse-mylyn-wikitext is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:97628"/>
          <criterion comment="eclipse-mylyn-webtasks is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:97959"/>
          <criterion comment="eclipse-mylyn-cdt is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:97876"/>
          <criterion comment="eclipse-mylyn-trac is earlier than 0:3.4.2-9.el6" test_ref="oval:org.mitre.oval:tst:97974"/>
          <criterion comment="eclipse-cdt is earlier than 1:7.0.1-4.el6" test_ref="oval:org.mitre.oval:tst:97723"/>
          <criterion comment="eclipse-cdt-parsers is earlier than 1:7.0.1-4.el6" test_ref="oval:org.mitre.oval:tst:97905"/>
          <criterion comment="eclipse-cdt-sdk is earlier than 1:7.0.1-4.el6" test_ref="oval:org.mitre.oval:tst:97768"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21598" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0283: kernel security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0283-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0283.html"/>
        <reference source="CVE" ref_id="CVE-2010-4165" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4165.html"/>
        <reference source="CVE" ref_id="CVE-2010-4169" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4169.html"/>
        <reference source="CVE" ref_id="CVE-2010-4243" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4243.html"/>
        <description>fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:19.489-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:21.437-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:46.316-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:97377"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:97481"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:97414"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:97440"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:96934"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:97539"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:97524"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:97389"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:97470"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:97235"/>
          <criterion comment="kernel is earlier than 0:2.6.32-71.18.1.el6" test_ref="oval:org.mitre.oval:tst:97393"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21596" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1151: openldap security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1151-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1151.html"/>
        <reference source="CESA" ref_id="CESA-2012:1151"/>
        <reference source="CVE" ref_id="CVE-2012-2668" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2668.html"/>
        <description>libraries/libldap/tls_m.c in OpenLDAP, possibly 2.4.31 and earlier, when using the Mozilla NSS backend, always uses the default cipher suite even when TLSCipherSuite is set, which might cause OpenLDAP to use weaker ciphers than intended and make it easier for remote attackers to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:43.048-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:21.278-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:46.061-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openldap-servers is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:93456"/>
          <criterion comment="openldap is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:94036"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:93855"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:93877"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.23-26.el6_3.2" test_ref="oval:org.mitre.oval:tst:94178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21595" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1110: foomatic security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>foomatic</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1110-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1110.html"/>
        <reference source="CVE" ref_id="CVE-2011-2964" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2964.html"/>
        <description>foomaticrip.c in foomatic-rip in foomatic-filters in Foomatic 4.0.6 allows remote attackers to execute arbitrary code via a crafted *FoomaticRIPCommandLine field in a .ppd file, a different vulnerability than CVE-2011-2697.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:20.454-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:21.220-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:45.976-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="foomatic is earlier than 0:4.0.4-1.el6_1.1" test_ref="oval:org.mitre.oval:tst:98152"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21594" version="187" class="patch">
      <metadata>
        <title>RHSA-2012:1346: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1346-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1346.html"/>
        <reference source="CVE" ref_id="CVE-2012-5248" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5248.html"/>
        <reference source="CVE" ref_id="CVE-2012-5249" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5249.html"/>
        <reference source="CVE" ref_id="CVE-2012-5250" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5250.html"/>
        <reference source="CVE" ref_id="CVE-2012-5251" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5251.html"/>
        <reference source="CVE" ref_id="CVE-2012-5252" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5252.html"/>
        <reference source="CVE" ref_id="CVE-2012-5253" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5253.html"/>
        <reference source="CVE" ref_id="CVE-2012-5254" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5254.html"/>
        <reference source="CVE" ref_id="CVE-2012-5255" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5255.html"/>
        <reference source="CVE" ref_id="CVE-2012-5256" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5256.html"/>
        <reference source="CVE" ref_id="CVE-2012-5257" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5257.html"/>
        <reference source="CVE" ref_id="CVE-2012-5258" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5258.html"/>
        <reference source="CVE" ref_id="CVE-2012-5259" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5259.html"/>
        <reference source="CVE" ref_id="CVE-2012-5260" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5260.html"/>
        <reference source="CVE" ref_id="CVE-2012-5261" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5261.html"/>
        <reference source="CVE" ref_id="CVE-2012-5262" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5262.html"/>
        <reference source="CVE" ref_id="CVE-2012-5263" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5263.html"/>
        <reference source="CVE" ref_id="CVE-2012-5264" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5264.html"/>
        <reference source="CVE" ref_id="CVE-2012-5265" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5265.html"/>
        <reference source="CVE" ref_id="CVE-2012-5266" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5266.html"/>
        <reference source="CVE" ref_id="CVE-2012-5267" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5267.html"/>
        <reference source="CVE" ref_id="CVE-2012-5268" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5268.html"/>
        <reference source="CVE" ref_id="CVE-2012-5269" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5269.html"/>
        <reference source="CVE" ref_id="CVE-2012-5270" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5270.html"/>
        <reference source="CVE" ref_id="CVE-2012-5271" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5271.html"/>
        <reference source="CVE" ref_id="CVE-2012-5272" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5272.html"/>
        <reference source="CVE" ref_id="CVE-2012-5285" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5285.html"/>
        <reference source="CVE" ref_id="CVE-2012-5286" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5286.html"/>
        <reference source="CVE" ref_id="CVE-2012-5287" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5287.html"/>
        <reference source="CVE" ref_id="CVE-2012-5673" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5673.html"/>
        <description>Unspecified vulnerability in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adobe AIR before 3.4.0.2710; and Adobe AIR SDK before 3.4.0.2710 has unknown impact and attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:09.048-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:20.644-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:45.359-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21594 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:34.047-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:07.196-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.243-1.el5" test_ref="oval:org.mitre.oval:tst:137898"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.243-1.el6" test_ref="oval:org.mitre.oval:tst:93757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21593" version="198" class="patch">
      <metadata>
        <title>RHSA-2012:1384: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1384-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1384.html"/>
        <reference source="CESA" ref_id="CESA-2012:1384"/>
        <reference source="CVE" ref_id="CVE-2012-3216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3216.html"/>
        <reference source="CVE" ref_id="CVE-2012-4416" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4416.html"/>
        <reference source="CVE" ref_id="CVE-2012-5068" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5068.html"/>
        <reference source="CVE" ref_id="CVE-2012-5069" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5069.html"/>
        <reference source="CVE" ref_id="CVE-2012-5071" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5071.html"/>
        <reference source="CVE" ref_id="CVE-2012-5072" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5072.html"/>
        <reference source="CVE" ref_id="CVE-2012-5073" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5073.html"/>
        <reference source="CVE" ref_id="CVE-2012-5075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5075.html"/>
        <reference source="CVE" ref_id="CVE-2012-5077" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5077.html"/>
        <reference source="CVE" ref_id="CVE-2012-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5079.html"/>
        <reference source="CVE" ref_id="CVE-2012-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5081.html"/>
        <reference source="CVE" ref_id="CVE-2012-5084" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5084.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2012-5086" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5086.html"/>
        <reference source="CVE" ref_id="CVE-2012-5089" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5089.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:22.957-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:20.565-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:45.249-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:94731"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:94780"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:94315"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:94761"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" test_ref="oval:org.mitre.oval:tst:94554"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21586" version="263" class="patch">
      <metadata>
        <title>RHSA-2012:1386: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1386-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1386.html"/>
        <reference source="CESA" ref_id="CESA-2012:1386"/>
        <reference source="CVE" ref_id="CVE-2012-3216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3216.html"/>
        <reference source="CVE" ref_id="CVE-2012-4416" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4416.html"/>
        <reference source="CVE" ref_id="CVE-2012-5068" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5068.html"/>
        <reference source="CVE" ref_id="CVE-2012-5069" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5069.html"/>
        <reference source="CVE" ref_id="CVE-2012-5070" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5070.html"/>
        <reference source="CVE" ref_id="CVE-2012-5071" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5071.html"/>
        <reference source="CVE" ref_id="CVE-2012-5072" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5072.html"/>
        <reference source="CVE" ref_id="CVE-2012-5073" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5073.html"/>
        <reference source="CVE" ref_id="CVE-2012-5074" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5074.html"/>
        <reference source="CVE" ref_id="CVE-2012-5075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5075.html"/>
        <reference source="CVE" ref_id="CVE-2012-5076" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5076.html"/>
        <reference source="CVE" ref_id="CVE-2012-5077" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5077.html"/>
        <reference source="CVE" ref_id="CVE-2012-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5079.html"/>
        <reference source="CVE" ref_id="CVE-2012-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5081.html"/>
        <reference source="CVE" ref_id="CVE-2012-5084" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5084.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2012-5086" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5086.html"/>
        <reference source="CVE" ref_id="CVE-2012-5087" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5087.html"/>
        <reference source="CVE" ref_id="CVE-2012-5088" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5088.html"/>
        <reference source="CVE" ref_id="CVE-2012-5089" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5089.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:43.644-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:20.022-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:44.464-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.3.el6_3.1" test_ref="oval:org.mitre.oval:tst:94689"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.3.el6_3.1" test_ref="oval:org.mitre.oval:tst:94165"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.3.el6_3.1" test_ref="oval:org.mitre.oval:tst:94578"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.3.el6_3.1" test_ref="oval:org.mitre.oval:tst:94620"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.3.el6_3.1" test_ref="oval:org.mitre.oval:tst:94840"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21585" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1461: libproxy security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libproxy</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1461-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1461.html"/>
        <reference source="CESA" ref_id="CESA-2012:1461"/>
        <reference source="CVE" ref_id="CVE-2012-4505" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4505.html"/>
        <description>Heap-based buffer overflow in the px_pac_reload function in lib/pac.c in libproxy 0.2.x and 0.3.x allows remote servers to have an unspecified impact via a crafted Content-Length size in an HTTP response header for a proxy.pac file request, a different vulnerability than CVE-2012-4504.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:22.261-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:19.932-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:44.339-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libproxy-bin is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:94812"/>
          <criterion comment="libproxy-mozjs is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:94742"/>
          <criterion comment="libproxy-devel is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:94584"/>
          <criterion comment="libproxy-webkit is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:94787"/>
          <criterion comment="libproxy is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:94057"/>
          <criterion comment="libproxy-gnome is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:94708"/>
          <criterion comment="libproxy-python is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:94799"/>
          <criterion comment="libproxy-kde is earlier than 0:0.3.0-3.el6_3" test_ref="oval:org.mitre.oval:tst:94190"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21584" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0309: pango security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>pango</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0309-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0309.html"/>
        <reference source="CVE" ref_id="CVE-2011-0064" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0064.html"/>
        <description>The hb_buffer_ensure function in hb-buffer.c in HarfBuzz, as used in Pango 1.28.3, Firefox, and other products, does not verify that memory reallocations succeed, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via crafted OpenType font data that triggers use of an incorrect index.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:13.978-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:19.871-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:44.227-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pango is earlier than 0:1.28.1-3.el6_0.5" test_ref="oval:org.mitre.oval:tst:97053"/>
          <criterion comment="pango-devel is earlier than 0:1.28.1-3.el6_0.5" test_ref="oval:org.mitre.oval:tst:97372"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21581" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0884: openssh security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssh</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0884-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0884.html"/>
        <reference source="CESA" ref_id="CESA-2012:0884"/>
        <reference source="CVE" ref_id="CVE-2011-5000" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5000.html"/>
        <description>The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field.  NOTE: there may be limited scenarios in which this issue is relevant.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:23.942-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:19.793-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:44.112-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssh-askpass is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:93494"/>
          <criterion comment="openssh-server is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:93842"/>
          <criterion comment="pam_ssh_agent_auth is earlier than 0:0.9-81.el6" test_ref="oval:org.mitre.oval:tst:93589"/>
          <criterion comment="openssh-clients is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:93815"/>
          <criterion comment="openssh-ldap is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:93971"/>
          <criterion comment="openssh is earlier than 0:5.3p1-81.el6" test_ref="oval:org.mitre.oval:tst:93915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21580" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:1009: java-1.7.0-openjdk security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1009-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1009.html"/>
        <reference source="CESA" ref_id="CESA-2012:1009"/>
        <reference source="CVE" ref_id="CVE-2012-1711" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1711.html"/>
        <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
        <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
        <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
        <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
        <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
        <reference source="CVE" ref_id="CVE-2012-1723" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1723.html"/>
        <reference source="CVE" ref_id="CVE-2012-1724" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1724.html"/>
        <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
        <reference source="CVE" ref_id="CVE-2012-1726" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1726.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:19.464-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:19.554-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:43.830-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.5-2.2.1.el6_3" test_ref="oval:org.mitre.oval:tst:93700"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.5-2.2.1.el6_3" test_ref="oval:org.mitre.oval:tst:93695"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.5-2.2.1.el6_3" test_ref="oval:org.mitre.oval:tst:93994"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.5-2.2.1.el6_3" test_ref="oval:org.mitre.oval:tst:93681"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.5-2.2.1.el6_3" test_ref="oval:org.mitre.oval:tst:93746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21578" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1288: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1288-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1288.html"/>
        <reference source="CESA" ref_id="CESA-2012:1288"/>
        <reference source="CVE" ref_id="CVE-2011-3102" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3102.html"/>
        <reference source="CVE" ref_id="CVE-2012-2807" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2807.html"/>
        <description>Multiple integer overflows in libxml2, as used in Google Chrome before 20.0.1132.43 and other products, on 64-bit Linux platforms allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:04.927-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:19.414-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:43.712-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:94291"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:94654"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.5" test_ref="oval:org.mitre.oval:tst:94642"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:94610"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:94685"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:94543"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.3" test_ref="oval:org.mitre.oval:tst:94284"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21577" version="68" class="patch">
      <metadata>
        <title>RHSA-2012:1304: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1304-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1304.html"/>
        <reference source="CESA" ref_id="CESA-2012:1304"/>
        <reference source="CVE" ref_id="CVE-2012-2313" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2313.html"/>
        <reference source="CVE" ref_id="CVE-2012-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2384.html"/>
        <reference source="CVE" ref_id="CVE-2012-2390" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2390.html"/>
        <reference source="CVE" ref_id="CVE-2012-3430" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3430.html"/>
        <reference source="CVE" ref_id="CVE-2012-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3552.html"/>
        <description>Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network traffic.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:18.166-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:03:19.253-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:43.518-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94468"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94097"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94175"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94317"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94261"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94652"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94573"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94270"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94581"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94162"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94089"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.9.1.el6" test_ref="oval:org.mitre.oval:tst:94437"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21575" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1234: qemu-kvm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1234-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1234.html"/>
        <reference source="CESA" ref_id="CESA-2012:1234"/>
        <reference source="CVE" ref_id="CVE-2012-3515" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3515.html"/>
        <description>Qemu, as used in Xen 4.0, 4.1 and possibly other products, when emulating certain devices with a virtual console backend, allows local OS guest users to gain privileges via a crafted escape VT100 sequence that triggers the overwrite of a "device model's address space."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:35.651-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:59.161-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:43.395-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:94436"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:94505"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:93886"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.295.el6_3.2" test_ref="oval:org.mitre.oval:tst:93795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21574" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1326: freeradius security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>freeradius</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1326-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1326.html"/>
        <reference source="CESA" ref_id="CESA-2012:1326"/>
        <reference source="CVE" ref_id="CVE-2012-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3547.html"/>
        <description>Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:35.036-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:59.084-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:43.280-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="freeradius-mysql is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:94616"/>
          <criterion comment="freeradius-perl is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:94622"/>
          <criterion comment="freeradius-unixODBC is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:94701"/>
          <criterion comment="freeradius-krb5 is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:94668"/>
          <criterion comment="freeradius-python is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:94741"/>
          <criterion comment="freeradius-utils is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:94426"/>
          <criterion comment="freeradius-ldap is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:94566"/>
          <criterion comment="freeradius-postgresql is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:94683"/>
          <criterion comment="freeradius is earlier than 0:2.1.12-4.el6_3" test_ref="oval:org.mitre.oval:tst:94447"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21572" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1037: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1037-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1037.html"/>
        <reference source="CESA" ref_id="CESA-2012:1037"/>
        <reference source="CVE" ref_id="CVE-2012-2143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2143.html"/>
        <reference source="CVE" ref_id="CVE-2012-2655" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2655.html"/>
        <description>PostgreSQL 8.3.x before 8.3.19, 8.4.x before 8.4.12, 9.0.x before 9.0.8, and 9.1.x before 9.1.4 allows remote authenticated users to cause a denial of service (server crash) by adding the (1) SECURITY DEFINER or (2) SET attributes to a procedural language's call handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:13.811-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.960-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:43.081-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql84-server is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93881"/>
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93900"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93926"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93699"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93932"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93797"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93970"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93714"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93347"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93632"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:94042"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.12-1.el5_8" test_ref="oval:org.mitre.oval:tst:93102"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93554"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93318"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:94020"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:94103"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:94054"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93750"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:94075"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93806"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93585"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.12-1.el6_2" test_ref="oval:org.mitre.oval:tst:93947"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21570" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1139: bind-dyndb-ldap security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind-dyndb-ldap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1139-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1139.html"/>
        <reference source="CESA" ref_id="CESA-2012:1139"/>
        <reference source="CVE" ref_id="CVE-2012-3429" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3429.html"/>
        <description>The dns_to_ldap_dn_escape function in src/ldap_convert.c in bind-dyndb-ldap 1.1.0rc1 and earlier does not properly escape distinguished names (DN) for LDAP queries, which allows remote DNS servers to cause a denial of service (named service hang) via a "$" character in a DN in a DNS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:33.171-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.888-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:42.975-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="bind-dyndb-ldap is earlier than 0:1.1.0-0.9.b1.el6_3.1" test_ref="oval:org.mitre.oval:tst:94241"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21566" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0328: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0328-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0328.html"/>
        <reference source="CVE" ref_id="CVE-2011-0715" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0715.html"/>
        <description>The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:59.591-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.607-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:42.516-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="subversion-ruby is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:97140"/>
          <criterion comment="subversion-kde is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:96604"/>
          <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:97080"/>
          <criterion comment="subversion-javahl is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:97296"/>
          <criterion comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:97531"/>
          <criterion comment="subversion-devel is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:96995"/>
          <criterion comment="subversion-gnome is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:97422"/>
          <criterion comment="subversion-perl is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:97475"/>
          <criterion comment="subversion is earlier than 0:1.6.11-2.el6_0.3" test_ref="oval:org.mitre.oval:tst:96822"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21559" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0329: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0329-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0329.html"/>
        <reference source="CVE" ref_id="CVE-2011-0714" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0714.html"/>
        <description>Use-after-free vulnerability in a certain Red Hat patch for the RPC server sockets functionality in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 might allow remote attackers to cause a denial of service (crash) via malformed data in a packet, related to lockd and the svc_xprt_received function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:23.065-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.438-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:42.286-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:97582"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:97585"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:97358"/>
          <criterion comment="perf is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:96961"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:97584"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:97403"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:97506"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:97298"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:97583"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:97192"/>
          <criterion comment="kernel is earlier than 0:2.6.32-71.18.2.el6" test_ref="oval:org.mitre.oval:tst:97315"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21558" version="159" class="patch">
      <metadata>
        <title>RHSA-2011:1380: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1380-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1380.html"/>
        <reference source="CESA" ref_id="CESA-2011:1380"/>
        <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html"/>
        <reference source="CVE" ref_id="CVE-2011-3521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3521.html"/>
        <reference source="CVE" ref_id="CVE-2011-3544" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3544.html"/>
        <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html"/>
        <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html"/>
        <reference source="CVE" ref_id="CVE-2011-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3551.html"/>
        <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html"/>
        <reference source="CVE" ref_id="CVE-2011-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3553.html"/>
        <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html"/>
        <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html"/>
        <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html"/>
        <reference source="CVE" ref_id="CVE-2011-3558" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3558.html"/>
        <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality and integrity, related to JSSE.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:47.013-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.141-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:41.895-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:98587"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:98352"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:98615"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:98606"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" test_ref="oval:org.mitre.oval:tst:98551"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:98164"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:98189"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:98527"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:98182"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" test_ref="oval:org.mitre.oval:tst:97671"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21555" version="5" class="patch">
      <metadata>
        <title>RHSA-2012:0987: sblim-cim-client2 security update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>sblim-cim-client2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0987-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0987.html"/>
        <reference source="CESA" ref_id="CESA-2012:0987"/>
        <reference source="CVE" ref_id="CVE-2012-2328" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2328.html"/>
        <description>internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) before 2.1.12 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:57.181-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:58.072-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:41.795-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="sblim-cim-client2-manual is earlier than 0:2.1.3-2.el6" test_ref="oval:org.mitre.oval:tst:93741"/>
          <criterion comment="sblim-cim-client2 is earlier than 0:2.1.3-2.el6" test_ref="oval:org.mitre.oval:tst:93712"/>
          <criterion comment="sblim-cim-client2-javadoc is earlier than 0:2.1.3-2.el6" test_ref="oval:org.mitre.oval:tst:93885"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21554" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0796: rsyslog security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>rsyslog</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0796-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0796.html"/>
        <reference source="CESA" ref_id="CESA-2012:0796"/>
        <reference source="CVE" ref_id="CVE-2011-4623" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4623.html"/>
        <description>Integer overflow in the rsCStrExtendBuf function in runtime/stringbuf.c in the imfile module in rsyslog 4.x before 4.6.6, 5.x before 5.7.4, and 6.x before 6.1.4 allows local users to cause a denial of service (daemon hang) via a large file, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:35.140-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.995-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:41.674-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="rsyslog-gssapi is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:93899"/>
          <criterion comment="rsyslog-relp is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:93427"/>
          <criterion comment="rsyslog-snmp is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:93844"/>
          <criterion comment="rsyslog-gnutls is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:93643"/>
          <criterion comment="rsyslog-pgsql is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:93679"/>
          <criterion comment="rsyslog is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:93038"/>
          <criterion comment="rsyslog-mysql is earlier than 0:5.8.10-2.el6" test_ref="oval:org.mitre.oval:tst:93518"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21553" version="5" class="patch">
      <metadata>
        <title>RHSA-2012:0973: nss, nss-util, and nspr security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0973-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0973.html"/>
        <reference source="CESA" ref_id="CESA-2012:0973"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

It was found that a Certificate Authority (CA) issued a subordinate CA
certificate to its customer, that could be used to issue certificates for
any name. This update renders the subordinate CA certificate as untrusted.
(BZ#798533)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

The nspr package has been upgraded to upstream version 4.9, which provides
a number of bug fixes and enhancements over the previous version.
(BZ#799193)

The nss-util package has been upgraded to upstream version 3.13.3, which
provides a number of bug fixes and enhancements over the previous version.
(BZ#799192)

The nss package has been upgraded to upstream version 3.13.3, which
provides numerous bug fixes and enhancements over the previous version. In
particular, SSL 2.0 is now disabled by default, support for SHA-224 has
been added, PORT_ErrorToString and PORT_ErrorToName now return the error
message and symbolic name of an NSS error code, and NSS_GetVersion now
returns the NSS version string. (BZ#744070)

These updated nss, nss-util, and nspr packages also provide fixes for the
following bugs:

* A PEM module internal function did not clean up memory when detecting a
non-existent file name. Consequently, memory leaks in client code occurred.
The code has been improved to deallocate such temporary objects and as a
result the reported memory leakage is gone. (BZ#746632)

* Recent changes to NSS re-introduced a problem where applications could
not use multiple SSL client certificates in the same process. Therefore,
any attempt to run commands that worked with multiple SSL client
certificates, such as the "yum repolist" command, resulted in a
re-negotiation handshake failure. With this update, a revised patch
correcting this problem has been applied to NSS, and using multiple SSL
client certificates in the same process is now possible again. (BZ#761086)

* The PEM module did not fully initialize newly constructed objects with
function pointers set to NULL. Consequently, a segmentation violation in
libcurl was sometimes experienced while accessing a package repository.
With this update, the code has been changed to fully initialize newly
allocated objects. As a result, updates can now be installed without
problems. (BZ#768669)

* A lack-of-robustness flaw caused the administration server for Red Hat
Directory Server to terminate unexpectedly because the mod_nss module made
nss calls before initializing nss as per the documented API. With this
update, nss protects itself against being called before it has been
properly initialized by the caller. (BZ#784674)

* Compilation errors occurred with some compilers when compiling code
against NSS 3.13.1. The following error message was displayed:

pkcs11n.h:365:26: warning: "__GNUC_MINOR" is not defined

An upstream patch has been applied to improve the code and the problem no
longer occurs. (BZ#795693)

* Unexpected terminations were reported in the messaging daemon (qpidd)
included in Red Hat Enterprise MRG after a recent update to nss. This
occurred because qpidd made nss calls before initializing nss. These
updated packages prevent qpidd and other affected processes that call nss
without initializing as mandated by the API from crashing. (BZ#797426)

Users of NSS, NSPR, and nss-util are advised to upgrade to these updated
packages, which fix these issues and add these enhancements. After
installing this update, applications using NSS, NSPR, or nss-util must be
restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:13.696-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.934-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:41.586-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21553 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:40.040-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:40.009-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nspr is earlier than 0:4.9-1.el6" test_ref="oval:org.mitre.oval:tst:93524"/>
          <criterion comment="nspr-devel is earlier than 0:4.9-1.el6" test_ref="oval:org.mitre.oval:tst:93367"/>
          <criterion comment="nss-util is earlier than 0:3.13.3-2.el6" test_ref="oval:org.mitre.oval:tst:94013"/>
          <criterion comment="nss-util-devel is earlier than 0:3.13.3-2.el6" test_ref="oval:org.mitre.oval:tst:93843"/>
          <criterion comment="nss-tools is earlier than 0:3.13.3-6.el6" test_ref="oval:org.mitre.oval:tst:93861"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.3-6.el6" test_ref="oval:org.mitre.oval:tst:93729"/>
          <criterion comment="nss-sysinit is earlier than 0:3.13.3-6.el6" test_ref="oval:org.mitre.oval:tst:93686"/>
          <criterion comment="nss is earlier than 0:3.13.3-6.el6" test_ref="oval:org.mitre.oval:tst:93538"/>
          <criterion comment="nss-devel is earlier than 0:3.13.3-6.el6" test_ref="oval:org.mitre.oval:tst:93698"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21550" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1434: icedtea-web security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1434-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1434.html"/>
        <reference source="CESA" ref_id="CESA-2012:1434"/>
        <reference source="CVE" ref_id="CVE-2012-4540" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4540.html"/>
        <description>Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:42.393-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.797-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:41.393-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.2.2-1.el6_3" test_ref="oval:org.mitre.oval:tst:94823"/>
          <criterion comment="icedtea-web is earlier than 0:1.2.2-1.el6_3" test_ref="oval:org.mitre.oval:tst:94673"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21545" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1362: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1362-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1362.html"/>
        <reference source="CESA" ref_id="CESA-2012:1362"/>
        <reference source="CVE" ref_id="CVE-2012-4193" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4193.html"/>
        <description>Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:45.046-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.491-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:40.864-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:94682"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el5.centos" test_ref="oval:org.mitre.oval:tst:94643"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:94674"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.8-2.el6.centos" test_ref="oval:org.mitre.oval:tst:95016"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21544" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1422: openswan security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1422-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1422.html"/>
        <reference source="CESA" ref_id="CESA-2011:1422"/>
        <reference source="CVE" ref_id="CVE-2011-4073" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4073.html"/>
        <description>Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (pluto IKE daemon crash) via vectors related to the (1) quick_outI1_continue and (2) quick_outI1 functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:28.499-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.381-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:40.763-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:98644"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.21-5.el5_7.6" test_ref="oval:org.mitre.oval:tst:98117"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:98111"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.4" test_ref="oval:org.mitre.oval:tst:98724"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21543" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1064: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1064-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1064.html"/>
        <reference source="CESA" ref_id="CESA-2012:1064"/>
        <reference source="CVE" ref_id="CVE-2012-2744" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2744.html"/>
        <reference source="CVE" ref_id="CVE-2012-2745" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2745.html"/>
        <description>The copy_creds function in kernel/cred.c in the Linux kernel before 3.3.2 provides an invalid replacement session keyring to a child process, which allows local users to cause a denial of service (panic) via a crafted application that uses the fork system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:01.597-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:57.219-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:40.630-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:94082"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:93668"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:94146"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:93665"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:93824"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:93771"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:93168"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:93202"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:94003"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:93630"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:94141"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.1.1.el6" test_ref="oval:org.mitre.oval:tst:94034"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21541" version="263" class="patch">
      <metadata>
        <title>RHSA-2012:1350: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1350-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1350.html"/>
        <reference source="CESA" ref_id="CESA-2012:1350"/>
        <reference source="CVE" ref_id="CVE-2012-1956" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1956.html"/>
        <reference source="CVE" ref_id="CVE-2012-3982" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3982.html"/>
        <reference source="CVE" ref_id="CVE-2012-3986" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3986.html"/>
        <reference source="CVE" ref_id="CVE-2012-3988" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3988.html"/>
        <reference source="CVE" ref_id="CVE-2012-3990" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3990.html"/>
        <reference source="CVE" ref_id="CVE-2012-3991" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3991.html"/>
        <reference source="CVE" ref_id="CVE-2012-3992" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3992.html"/>
        <reference source="CVE" ref_id="CVE-2012-3993" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3993.html"/>
        <reference source="CVE" ref_id="CVE-2012-3994" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3994.html"/>
        <reference source="CVE" ref_id="CVE-2012-3995" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3995.html"/>
        <reference source="CVE" ref_id="CVE-2012-4179" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4179.html"/>
        <reference source="CVE" ref_id="CVE-2012-4180" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4180.html"/>
        <reference source="CVE" ref_id="CVE-2012-4181" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4181.html"/>
        <reference source="CVE" ref_id="CVE-2012-4182" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4182.html"/>
        <reference source="CVE" ref_id="CVE-2012-4183" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4183.html"/>
        <reference source="CVE" ref_id="CVE-2012-4184" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4184.html"/>
        <reference source="CVE" ref_id="CVE-2012-4185" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4185.html"/>
        <reference source="CVE" ref_id="CVE-2012-4186" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4186.html"/>
        <reference source="CVE" ref_id="CVE-2012-4187" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4187.html"/>
        <reference source="CVE" ref_id="CVE-2012-4188" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4188.html"/>
        <description>Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:31.164-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:56.304-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:40.074-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:94485"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:94662"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.8-1.el5.centos" test_ref="oval:org.mitre.oval:tst:95071"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:94736"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:94408"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:94348"/>
            <criterion comment="firefox is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:94541"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94385"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94983"/>
            <criterion comment="firefox is earlier than 0:10.0.8-1.el6.centos" test_ref="oval:org.mitre.oval:tst:95006"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21538" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0902: cifs-utils security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>cifs-utils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0902-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0902.html"/>
        <reference source="CESA" ref_id="CESA-2012:0902"/>
        <reference source="CVE" ref_id="CVE-2012-1586" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1586.html"/>
        <description>mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:05.264-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:56.208-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:39.977-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="cifs-utils is earlier than 0:4.8.1-10.el6" test_ref="oval:org.mitre.oval:tst:94035"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21534" version="55" class="patch">
      <metadata>
        <title>RHSA-2011:0195: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0195-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0195.html"/>
        <reference source="CVE" ref_id="CVE-2009-5016" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5016.html"/>
        <reference source="CVE" ref_id="CVE-2010-3709" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3709.html"/>
        <reference source="CVE" ref_id="CVE-2010-3870" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3870.html"/>
        <reference source="CVE" ref_id="CVE-2010-4645" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4645.html"/>
        <description>strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:45.122-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:55.864-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:39.785-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php-pdo is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97264"/>
          <criterion comment="php-common is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:96866"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97022"/>
          <criterion comment="php-embedded is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97320"/>
          <criterion comment="php-snmp is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:96729"/>
          <criterion comment="php-enchant is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97348"/>
          <criterion comment="php-pgsql is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97069"/>
          <criterion comment="php-recode is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97341"/>
          <criterion comment="php-devel is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97160"/>
          <criterion comment="php is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:96842"/>
          <criterion comment="php-gd is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:96385"/>
          <criterion comment="php-imap is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97244"/>
          <criterion comment="php-odbc is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97116"/>
          <criterion comment="php-soap is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:96975"/>
          <criterion comment="php-tidy is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:96765"/>
          <criterion comment="php-mysql is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97186"/>
          <criterion comment="php-bcmath is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97136"/>
          <criterion comment="php-zts is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97297"/>
          <criterion comment="php-intl is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97173"/>
          <criterion comment="php-process is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97337"/>
          <criterion comment="php-ldap is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97011"/>
          <criterion comment="php-mbstring is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:96935"/>
          <criterion comment="php-dba is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:96379"/>
          <criterion comment="php-cli is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97251"/>
          <criterion comment="php-pspell is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97139"/>
          <criterion comment="php-xml is earlier than 0:5.3.2-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97222"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21533" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0958: sos security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>sos</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0958-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0958.html"/>
        <reference source="CESA" ref_id="CESA-2012:0958"/>
        <reference source="CVE" ref_id="CVE-2012-2664" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2664.html"/>
        <description>The sosreport utility in the Red Hat sos package before 2.2-29 does not remove the root user password information from the Kickstart configuration file (/root/anaconda-ks.cfg) when creating an archive of debugging information, which might allow attackers to obtain passwords or password hashes.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:58.497-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:55.767-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:39.706-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="sos is earlier than 0:2.2-29.el6" test_ref="oval:org.mitre.oval:tst:93976"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21532" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:1426: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1426-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1426.html"/>
        <reference source="CESA" ref_id="CESA-2012:1426"/>
        <reference source="CVE" ref_id="CVE-2012-1568" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1568.html"/>
        <reference source="CVE" ref_id="CVE-2012-2133" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2133.html"/>
        <reference source="CVE" ref_id="CVE-2012-3400" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3400.html"/>
        <reference source="CVE" ref_id="CVE-2012-3511" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3511.html"/>
        <description>Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:11.271-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:55.499-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:39.558-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94779"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94431"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94260"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94837"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94807"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94818"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94842"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94583"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94783"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94661"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94874"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.14.1.el6" test_ref="oval:org.mitre.oval:tst:94653"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21530" version="81" class="patch">
      <metadata>
        <title>RHSA-2012:1265: libxslt security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxslt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1265-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1265.html"/>
        <reference source="CESA" ref_id="CESA-2012:1265"/>
        <reference source="CVE" ref_id="CVE-2011-1202" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1202.html"/>
        <reference source="CVE" ref_id="CVE-2011-3970" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3970.html"/>
        <reference source="CVE" ref_id="CVE-2012-2825" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2825.html"/>
        <reference source="CVE" ref_id="CVE-2012-2870" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2870.html"/>
        <reference source="CVE" ref_id="CVE-2012-2871" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2871.html"/>
        <reference source="CVE" ref_id="CVE-2012-2893" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2893.html"/>
        <description>Double free vulnerability in libxslt, as used in Google Chrome before 22.0.1229.79, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XSL transforms.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:55.547-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:55.148-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:39.331-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxslt-devel is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:94297"/>
            <criterion comment="libxslt is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:94515"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.17-4.el5_8.3" test_ref="oval:org.mitre.oval:tst:94580"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxslt-devel is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:94414"/>
            <criterion comment="libxslt is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:94308"/>
            <criterion comment="libxslt-python is earlier than 0:1.1.26-2.el6_3.1" test_ref="oval:org.mitre.oval:tst:94603"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21528" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1551: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1551-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1551.html"/>
        <reference source="CESA" ref_id="CESA-2012:1551"/>
        <reference source="CVE" ref_id="CVE-2012-5611" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5611.html"/>
        <description>Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:40.408-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:54.917-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:39.090-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-server is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:94759"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:94856"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:94801"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:94660"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:94557"/>
          <criterion comment="mysql-test is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:94302"/>
          <criterion comment="mysql is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:94815"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.66-2.el6_3" test_ref="oval:org.mitre.oval:tst:94744"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21527" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1054: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1054-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1054.html"/>
        <reference source="CESA" ref_id="CESA-2012:1054"/>
        <reference source="CVE" ref_id="CVE-2012-2088" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2088.html"/>
        <reference source="CVE" ref_id="CVE-2012-2113" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2113.html"/>
        <description>Multiple integer overflows in tiff2pdf in libtiff before 4.0.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:05.776-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:54.750-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:38.958-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:93166"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-15.el5_8" test_ref="oval:org.mitre.oval:tst:93837"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:94058"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:94129"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-6.el6_3" test_ref="oval:org.mitre.oval:tst:94023"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21524" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0426: spice-xpi security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>spice-xpi</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0426-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0426.html"/>
        <reference source="CVE" ref_id="CVE-2011-0012" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0012.html"/>
        <reference source="CVE" ref_id="CVE-2011-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1179.html"/>
        <description>The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:44.264-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:54.033-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:38.464-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="spice-xpi is earlier than 0:2.4-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:97724"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21523" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0320: libcgroup security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libcgroup</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0320-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0320.html"/>
        <reference source="CVE" ref_id="CVE-2011-1006" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1006.html"/>
        <reference source="CVE" ref_id="CVE-2011-1022" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1022.html"/>
        <description>The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:22.108-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:53.889-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:38.341-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libcgroup-devel is earlier than 0:0.36.1-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97510"/>
          <criterion comment="libcgroup is earlier than 0:0.36.1-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97564"/>
          <criterion comment="libcgroup-pam is earlier than 0:0.36.1-6.el6_0.1" test_ref="oval:org.mitre.oval:tst:97303"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21522" version="55" class="patch">
      <metadata>
        <title>RHSA-2011:0311: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0311-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0311.html"/>
        <reference source="CVE" ref_id="CVE-2010-1585" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1585.html"/>
        <reference source="CVE" ref_id="CVE-2011-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0053.html"/>
        <reference source="CVE" ref_id="CVE-2011-0061" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0061.html"/>
        <reference source="CVE" ref_id="CVE-2011-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0062.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:51.404-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:53.664-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:38.133-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="thunderbird is earlier than 0:3.1.8-4.el6_0" test_ref="oval:org.mitre.oval:tst:97406"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21520" version="224" class="patch">
      <metadata>
        <title>RHSA-2012:1088: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1088-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1088.html"/>
        <reference source="CESA" ref_id="CESA-2012:1088"/>
        <reference source="CVE" ref_id="CVE-2012-1948" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1948.html"/>
        <reference source="CVE" ref_id="CVE-2012-1950" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1950.html"/>
        <reference source="CVE" ref_id="CVE-2012-1951" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1951.html"/>
        <reference source="CVE" ref_id="CVE-2012-1952" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1952.html"/>
        <reference source="CVE" ref_id="CVE-2012-1953" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1953.html"/>
        <reference source="CVE" ref_id="CVE-2012-1954" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1954.html"/>
        <reference source="CVE" ref_id="CVE-2012-1955" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1955.html"/>
        <reference source="CVE" ref_id="CVE-2012-1957" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1957.html"/>
        <reference source="CVE" ref_id="CVE-2012-1958" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1958.html"/>
        <reference source="CVE" ref_id="CVE-2012-1959" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1959.html"/>
        <reference source="CVE" ref_id="CVE-2012-1961" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1961.html"/>
        <reference source="CVE" ref_id="CVE-2012-1962" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1962.html"/>
        <reference source="CVE" ref_id="CVE-2012-1963" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1963.html"/>
        <reference source="CVE" ref_id="CVE-2012-1964" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1964.html"/>
        <reference source="CVE" ref_id="CVE-2012-1965" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1965.html"/>
        <reference source="CVE" ref_id="CVE-2012-1966" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1966.html"/>
        <reference source="CVE" ref_id="CVE-2012-1967" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1967.html"/>
        <description>Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:50.243-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:52.787-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:36.906-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-2.el5_8" test_ref="oval:org.mitre.oval:tst:93936"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-2.el5_8" test_ref="oval:org.mitre.oval:tst:93581"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.6-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94961"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.6-1.el5_8" test_ref="oval:org.mitre.oval:tst:93905"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:94048"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:94164"/>
            <criterion comment="firefox is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:94072"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94749"/>
            <criterion comment="xulrunner is earlier than 0:10.0.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94352"/>
            <criterion comment="firefox is earlier than 0:10.0.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94776"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21517" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:1225: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1225-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1225.html"/>
        <reference source="CVE" ref_id="CVE-2012-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0547.html"/>
        <reference source="CVE" ref_id="CVE-2012-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1682.html"/>
        <reference source="CVE" ref_id="CVE-2012-3136" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3136.html"/>
        <reference source="CVE" ref_id="CVE-2012-4681" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4681.html"/>
        <description>Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:34.407-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:52.459-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:36.467-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.7-1jpp.5.el6_3" test_ref="oval:org.mitre.oval:tst:94239"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.7-1jpp.5.el6_3" test_ref="oval:org.mitre.oval:tst:94180"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.7-1jpp.5.el6_3" test_ref="oval:org.mitre.oval:tst:94498"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.7-1jpp.5.el6_3" test_ref="oval:org.mitre.oval:tst:94176"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.7-1jpp.5.el6_3" test_ref="oval:org.mitre.oval:tst:94443"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21514" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1135: libreoffice security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libreoffice</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1135-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1135.html"/>
        <reference source="CESA" ref_id="CESA-2012:1135"/>
        <reference source="CVE" ref_id="CVE-2012-2665" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2665.html"/>
        <description>Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:30.979-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:51.962-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:35.902-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libreoffice-langpack-de is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94381"/>
          <criterion comment="libreoffice-langpack-sk is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94118"/>
          <criterion comment="libreoffice-langpack-hr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93993"/>
          <criterion comment="libreoffice-langpack-ro is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94108"/>
          <criterion comment="libreoffice-pyuno is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93299"/>
          <criterion comment="autocorr-af is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93215"/>
          <criterion comment="libreoffice-report-builder is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94148"/>
          <criterion comment="libreoffice-calc is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94114"/>
          <criterion comment="autocorr-vi is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94273"/>
          <criterion comment="libreoffice-langpack-ta is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94279"/>
          <criterion comment="libreoffice-math is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94159"/>
          <criterion comment="autocorr-ja is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93633"/>
          <criterion comment="autocorr-sr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94312"/>
          <criterion comment="libreoffice-langpack-bg is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93319"/>
          <criterion comment="autocorr-eu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94257"/>
          <criterion comment="libreoffice-langpack-eu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94280"/>
          <criterion comment="libreoffice-langpack-ja is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93666"/>
          <criterion comment="libreoffice-langpack-or is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94027"/>
          <criterion comment="libreoffice-langpack-hi is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94144"/>
          <criterion comment="autocorr-sl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93664"/>
          <criterion comment="libreoffice-langpack-zu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94234"/>
          <criterion comment="libreoffice-langpack-el is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94275"/>
          <criterion comment="autocorr-ga is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94022"/>
          <criterion comment="autocorr-mn is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94061"/>
          <criterion comment="libreoffice-langpack-cy is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94167"/>
          <criterion comment="libreoffice is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93491"/>
          <criterion comment="libreoffice-langpack-ga is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93884"/>
          <criterion comment="autocorr-pl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94272"/>
          <criterion comment="libreoffice-bsh is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93716"/>
          <criterion comment="libreoffice-langpack-cs is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94124"/>
          <criterion comment="libreoffice-langpack-tn is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94028"/>
          <criterion comment="libreoffice-base is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94313"/>
          <criterion comment="libreoffice-langpack-sr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94195"/>
          <criterion comment="autocorr-da is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93820"/>
          <criterion comment="libreoffice-pdfimport is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93303"/>
          <criterion comment="libreoffice-presenter-screen is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94174"/>
          <criterion comment="libreoffice-langpack-xh is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94232"/>
          <criterion comment="libreoffice-langpack-zh-Hans is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93790"/>
          <criterion comment="libreoffice-langpack-bn is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94299"/>
          <criterion comment="libreoffice-graphicfilter is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94286"/>
          <criterion comment="libreoffice-langpack-sl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93530"/>
          <criterion comment="libreoffice-langpack-ar is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94235"/>
          <criterion comment="libreoffice-langpack-th is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94250"/>
          <criterion comment="autocorr-sv is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94292"/>
          <criterion comment="autocorr-tr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93975"/>
          <criterion comment="libreoffice-xsltfilter is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93334"/>
          <criterion comment="libreoffice-langpack-te is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94019"/>
          <criterion comment="autocorr-fr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94238"/>
          <criterion comment="autocorr-es is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93916"/>
          <criterion comment="libreoffice-langpack-uk is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93829"/>
          <criterion comment="libreoffice-langpack-fr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93961"/>
          <criterion comment="libreoffice-langpack-ca is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94211"/>
          <criterion comment="libreoffice-javafilter is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93308"/>
          <criterion comment="libreoffice-langpack-af is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94191"/>
          <criterion comment="libreoffice-langpack-pl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94069"/>
          <criterion comment="libreoffice-langpack-es is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94140"/>
          <criterion comment="libreoffice-presentation-minimizer is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93461"/>
          <criterion comment="autocorr-fi is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94295"/>
          <criterion comment="libreoffice-langpack-mai is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94189"/>
          <criterion comment="libreoffice-langpack-nn is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94237"/>
          <criterion comment="libreoffice-langpack-mr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94010"/>
          <criterion comment="libreoffice-langpack-fi is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93411"/>
          <criterion comment="libreoffice-langpack-pt-PT is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94045"/>
          <criterion comment="libreoffice-core is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94243"/>
          <criterion comment="libreoffice-impress is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93908"/>
          <criterion comment="libreoffice-langpack-ml is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94117"/>
          <criterion comment="autocorr-de is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93382"/>
          <criterion comment="libreoffice-langpack-sv is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94227"/>
          <criterion comment="libreoffice-langpack-tr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93292"/>
          <criterion comment="libreoffice-ure is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93445"/>
          <criterion comment="libreoffice-draw is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93934"/>
          <criterion comment="libreoffice-langpack-kn is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93258"/>
          <criterion comment="libreoffice-langpack-ss is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93583"/>
          <criterion comment="libreoffice-langpack-nb is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94223"/>
          <criterion comment="libreoffice-ogltrans is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93974"/>
          <criterion comment="libreoffice-writer is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94203"/>
          <criterion comment="autocorr-nl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93830"/>
          <criterion comment="autocorr-bg is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93898"/>
          <criterion comment="libreoffice-langpack-as is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93998"/>
          <criterion comment="libreoffice-langpack-zh-Hant is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93951"/>
          <criterion comment="libreoffice-emailmerge is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93732"/>
          <criterion comment="libreoffice-langpack-gu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93857"/>
          <criterion comment="libreoffice-langpack-ur is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94289"/>
          <criterion comment="libreoffice-headless is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94115"/>
          <criterion comment="libreoffice-opensymbol-fonts is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94008"/>
          <criterion comment="libreoffice-sdk-doc is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94220"/>
          <criterion comment="libreoffice-langpack-da is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93597"/>
          <criterion comment="autocorr-ru is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94137"/>
          <criterion comment="libreoffice-langpack-ve is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94245"/>
          <criterion comment="libreoffice-langpack-nso is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93839"/>
          <criterion comment="libreoffice-langpack-gl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93354"/>
          <criterion comment="libreoffice-langpack-et is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94271"/>
          <criterion comment="autocorr-en is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94233"/>
          <criterion comment="libreoffice-langpack-he is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93752"/>
          <criterion comment="autocorr-sk is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93917"/>
          <criterion comment="libreoffice-langpack-nr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94126"/>
          <criterion comment="autocorr-lt is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94201"/>
          <criterion comment="libreoffice-langpack-ms is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93775"/>
          <criterion comment="autocorr-cs is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94152"/>
          <criterion comment="autocorr-pt is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94248"/>
          <criterion comment="libreoffice-langpack-dz is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94086"/>
          <criterion comment="libreoffice-langpack-en is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93875"/>
          <criterion comment="libreoffice-testtools is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94121"/>
          <criterion comment="libreoffice-gdb-debug-support is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93362"/>
          <criterion comment="libreoffice-langpack-nl is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93809"/>
          <criterion comment="libreoffice-langpack-lt is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94276"/>
          <criterion comment="autocorr-fa is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94012"/>
          <criterion comment="libreoffice-langpack-pa is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94236"/>
          <criterion comment="libreoffice-wiki-publisher is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93672"/>
          <criterion comment="libreoffice-langpack-pt-BR is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93825"/>
          <criterion comment="autocorr-zh is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94066"/>
          <criterion comment="autocorr-ko is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94214"/>
          <criterion comment="libreoffice-rhino is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94210"/>
          <criterion comment="libreoffice-langpack-ts is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94083"/>
          <criterion comment="autocorr-it is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93701"/>
          <criterion comment="libreoffice-langpack-st is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93835"/>
          <criterion comment="libreoffice-langpack-ko is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94135"/>
          <criterion comment="libreoffice-sdk is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93245"/>
          <criterion comment="libreoffice-langpack-ru is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93977"/>
          <criterion comment="autocorr-hu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93802"/>
          <criterion comment="libreoffice-langpack-it is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:93496"/>
          <criterion comment="libreoffice-langpack-hu is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94007"/>
          <criterion comment="autocorr-lb is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94120"/>
          <criterion comment="autocorr-hr is earlier than 1:3.4.5.2-16.1.el6_3" test_ref="oval:org.mitre.oval:tst:94156"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21513" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1269: qpid security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>python-qpid</product>
          <product>qpid-cpp</product>
          <product>qpid-qmf</product>
          <product>qpid-tools</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1269-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1269.html"/>
        <reference source="CESA" ref_id="CESA-2012:1269"/>
        <reference source="CVE" ref_id="CVE-2012-2145" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2145.html"/>
        <description>Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:39.371-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:51.822-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:35.692-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="python-qpid is earlier than 0:0.14-11.el6_3" test_ref="oval:org.mitre.oval:tst:94473"/>
          <criterion comment="ruby-qpid-qmf is earlier than 0:0.14-14.el6_3" test_ref="oval:org.mitre.oval:tst:94667"/>
          <criterion comment="qpid-qmf-devel is earlier than 0:0.14-14.el6_3" test_ref="oval:org.mitre.oval:tst:94259"/>
          <criterion comment="qpid-qmf is earlier than 0:0.14-14.el6_3" test_ref="oval:org.mitre.oval:tst:94198"/>
          <criterion comment="python-qpid-qmf is earlier than 0:0.14-14.el6_3" test_ref="oval:org.mitre.oval:tst:94345"/>
          <criterion comment="qpid-tools is earlier than 0:0.14-6.el6_3" test_ref="oval:org.mitre.oval:tst:93959"/>
          <criterion comment="qpid-cpp-client-devel is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94452"/>
          <criterion comment="qpid-cpp-server-devel is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94331"/>
          <criterion comment="qpid-cpp-client-rdma is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94594"/>
          <criterion comment="qpid-cpp-client-ssl is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94629"/>
          <criterion comment="qpid-cpp-server-cluster is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94157"/>
          <criterion comment="qpid-cpp is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94507"/>
          <criterion comment="qpid-cpp-server is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94329"/>
          <criterion comment="qpid-cpp-server-ssl is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94637"/>
          <criterion comment="rh-qpid-cpp-tests is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94648"/>
          <criterion comment="qpid-cpp-client is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94430"/>
          <criterion comment="qpid-cpp-server-xml is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94659"/>
          <criterion comment="qpid-cpp-client-devel-docs is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:93742"/>
          <criterion comment="qpid-cpp-server-rdma is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94249"/>
          <criterion comment="qpid-cpp-server-store is earlier than 0:0.14-22.el6_3" test_ref="oval:org.mitre.oval:tst:94700"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21505" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1068: openjpeg security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openjpeg</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1068-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1068.html"/>
        <reference source="CESA" ref_id="CESA-2012:1068"/>
        <reference source="CVE" ref_id="CVE-2009-5030" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5030.html"/>
        <reference source="CVE" ref_id="CVE-2012-3358" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3358.html"/>
        <description>Multiple heap-based buffer overflows in the j2k_read_sot function in j2k.c in OpenJPEG 1.5 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted (1) tile number or (2) tile length in a JPEG 2000 image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:12.235-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:51.674-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:35.556-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openjpeg-libs is earlier than 0:1.3-8.el6_3" test_ref="oval:org.mitre.oval:tst:94147"/>
          <criterion comment="openjpeg is earlier than 0:1.3-8.el6_3" test_ref="oval:org.mitre.oval:tst:93953"/>
          <criterion comment="openjpeg-devel is earlier than 0:1.3-8.el6_3" test_ref="oval:org.mitre.oval:tst:93249"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21504" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0899: openldap security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openldap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0899-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0899.html"/>
        <reference source="CESA" ref_id="CESA-2012:0899"/>
        <reference source="CVE" ref_id="CVE-2012-1164" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1164.html"/>
        <description>slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:34.056-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:51.553-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:35.452-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openldap-servers is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:93046"/>
          <criterion comment="openldap is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:93950"/>
          <criterion comment="openldap-clients is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:93811"/>
          <criterion comment="openldap-devel is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:93945"/>
          <criterion comment="openldap-servers-sql is earlier than 0:2.4.23-26.el6" test_ref="oval:org.mitre.oval:tst:93615"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21503" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0256: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0256.html"/>
        <reference source="CVE" ref_id="CVE-2011-0413" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0413.html"/>
        <description>The DHCPv6 server in ISC DHCP 4.0.x and 4.1.x before 4.1.2-P1, 4.0-ESV and 4.1-ESV before 4.1-ESV-R1, and 4.2.x before 4.2.1b1 allows remote attackers to cause a denial of service (assertion failure and daemon crash) by sending a message over IPv6 for a declined and abandoned address.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:28.873-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:51.456-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:35.360-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.2" test_ref="oval:org.mitre.oval:tst:97276"/>
          <criterion comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.2" test_ref="oval:org.mitre.oval:tst:97489"/>
          <criterion comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96539"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21501" version="44" class="patch">
      <metadata>
        <title>RHSA-2012:1569: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1569-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1569.html"/>
        <reference source="CVE" ref_id="CVE-2012-5676" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5676.html"/>
        <reference source="CVE" ref_id="CVE-2012-5677" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5677.html"/>
        <reference source="CVE" ref_id="CVE-2012-5678" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5678.html"/>
        <description>Adobe Flash Player before 10.3.183.48 and 11.x before 11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on Mac OS X, before 10.3.183.48 and 11.x before 11.2.202.258 on Linux, before 11.1.111.29 on Android 2.x and 3.x, and before 11.1.115.34 on Android 4.x; Adobe AIR before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X; and Adobe AIR SDK before 3.5.0.880 on Windows and before 3.5.0.890 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:05.063-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:51.174-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:35.097-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21501 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:06.339-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:06.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.258-1.el5" test_ref="oval:org.mitre.oval:tst:137796"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.258-1.el6" test_ref="oval:org.mitre.oval:tst:94561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21500" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0507: apr security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>apr</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0507-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0507.html"/>
        <reference source="CESA" ref_id="CESA-2011:0507"/>
        <reference source="CVE" ref_id="CVE-2011-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0419.html"/>
        <description>Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via *? sequences in the first argument, as demonstrated by attacks against mod_autoindex in httpd.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:00.001-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:51.002-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:34.990-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:97743"/>
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:97588"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_6.4" test_ref="oval:org.mitre.oval:tst:97624"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="apr-devel is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:97862"/>
            <criterion comment="apr is earlier than 0:1.3.9-3.el6_0.1" test_ref="oval:org.mitre.oval:tst:97591"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21499" version="120" class="patch">
      <metadata>
        <title>RHSA-2012:1046: php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1046-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1046.html"/>
        <reference source="CESA" ref_id="CESA-2012:1046"/>
        <reference source="CVE" ref_id="CVE-2010-2950" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2950.html"/>
        <reference source="CVE" ref_id="CVE-2011-4153" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4153.html"/>
        <reference source="CVE" ref_id="CVE-2012-0057" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0057.html"/>
        <reference source="CVE" ref_id="CVE-2012-0781" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0781.html"/>
        <reference source="CVE" ref_id="CVE-2012-0789" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0789.html"/>
        <reference source="CVE" ref_id="CVE-2012-1172" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1172.html"/>
        <reference source="CVE" ref_id="CVE-2012-2143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2143.html"/>
        <reference source="CVE" ref_id="CVE-2012-2336" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2336.html"/>
        <reference source="CVE" ref_id="CVE-2012-2386" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2386.html"/>
        <description>Integer overflow in the phar_parse_tarfile function in tar.c in the phar extension in PHP before 5.3.14 and 5.4.x before 5.4.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted tar file that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:48.542-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:45.525-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:34.606-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php-pdo is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93833"/>
          <criterion comment="php-common is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93656"/>
          <criterion comment="php-enchant is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:94063"/>
          <criterion comment="php-embedded is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93896"/>
          <criterion comment="php-snmp is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93923"/>
          <criterion comment="php-pgsql is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93671"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93250"/>
          <criterion comment="php-devel is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93431"/>
          <criterion comment="php-recode is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:94060"/>
          <criterion comment="php is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93876"/>
          <criterion comment="php-imap is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93912"/>
          <criterion comment="php-gd is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93121"/>
          <criterion comment="php-odbc is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93903"/>
          <criterion comment="php-tidy is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93536"/>
          <criterion comment="php-soap is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93897"/>
          <criterion comment="php-mysql is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93924"/>
          <criterion comment="php-zts is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:94064"/>
          <criterion comment="php-process is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:94104"/>
          <criterion comment="php-bcmath is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93988"/>
          <criterion comment="php-intl is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93810"/>
          <criterion comment="php-ldap is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93118"/>
          <criterion comment="php-mbstring is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93724"/>
          <criterion comment="php-dba is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93136"/>
          <criterion comment="php-cli is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93832"/>
          <criterion comment="php-pspell is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93678"/>
          <criterion comment="php-xml is earlier than 0:5.3.3-14.el6_3" test_ref="oval:org.mitre.oval:tst:93878"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21497" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0850: flash-plugin security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0850-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0850.html"/>
        <reference source="CVE" ref_id="CVE-2011-2107" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2107.html"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "universal cross-site scripting vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:16.470-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:45.374-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:34.384-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.181.22-1.el5" test_ref="oval:org.mitre.oval:tst:97939"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.181.22-1.el6" test_ref="oval:org.mitre.oval:tst:98085"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21496" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1123: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1123-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1123.html"/>
        <reference source="CESA" ref_id="CESA-2012:1123"/>
        <reference source="CVE" ref_id="CVE-2012-3817" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3817.html"/>
        <description>ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:56.512-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:45.278-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:34.253-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:93721"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:93566"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:94081"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:93247"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:93963"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:94163"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:94049"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" test_ref="oval:org.mitre.oval:tst:94122"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94192"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94170"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94208"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94079"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94099"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.2" test_ref="oval:org.mitre.oval:tst:94087"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21495" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0810: busybox security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>busybox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0810-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0810.html"/>
        <reference source="CESA" ref_id="CESA-2012:0810"/>
        <reference source="CVE" ref_id="CVE-2006-1168" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1168.html"/>
        <reference source="CVE" ref_id="CVE-2011-2716" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2716.html"/>
        <description>The DHCP client (udhcpc) in BusyBox before 1.20.0 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in the (1) HOST_NAME, (2) DOMAIN_NAME, (3) NIS_DOMAIN, and (4) TFTP_SERVER_NAME host name options.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:27.865-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:45.190-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:34.091-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="busybox-petitboot is earlier than 1:1.15.1-15.el6" test_ref="oval:org.mitre.oval:tst:93150"/>
          <criterion comment="busybox is earlier than 1:1.15.1-15.el6" test_ref="oval:org.mitre.oval:tst:92987"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21493" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0600: dovecot security and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>dovecot</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0600-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0600.html"/>
        <reference source="CVE" ref_id="CVE-2010-3707" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3707.html"/>
        <reference source="CVE" ref_id="CVE-2010-3780" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3780.html"/>
        <description>Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:48.689-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:45.111-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:33.961-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:97928"/>
          <criterion comment="dovecot-mysql is earlier than 1:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:97459"/>
          <criterion comment="dovecot is earlier than 1:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:97340"/>
          <criterion comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:97891"/>
          <criterion comment="dovecot-devel is earlier than 1:2.0.9-2.el6" test_ref="oval:org.mitre.oval:tst:97571"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21489" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0874: mysql security and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0874-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0874.html"/>
        <reference source="CESA" ref_id="CESA-2012:0874"/>
        <reference source="CVE" ref_id="CVE-2012-2102" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2102.html"/>
        <description>MySQL 5.1.x before 5.1.62 and 5.5.x before 5.5.22 allows remote authenticated users to cause a denial of service (assertion failure and mysqld abort) by deleting a record and using HANDLER READ NEXT.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:51.376-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:44.871-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:33.662-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:93608"/>
          <criterion comment="mysql-server is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:93663"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:93937"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:93505"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:93579"/>
          <criterion comment="mysql-test is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:93398"/>
          <criterion comment="mysql is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:93624"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.61-4.el6" test_ref="oval:org.mitre.oval:tst:93275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21487" version="94" class="patch">
      <metadata>
        <title>RHSA-2011:0856: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0856-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0856.html"/>
        <reference source="CVE" ref_id="CVE-2011-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-0864" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0864.html"/>
        <reference source="CVE" ref_id="CVE-2011-0865" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0865.html"/>
        <reference source="CVE" ref_id="CVE-2011-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0867.html"/>
        <reference source="CVE" ref_id="CVE-2011-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0868.html"/>
        <reference source="CVE" ref_id="CVE-2011-0869" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0869.html"/>
        <reference source="CVE" ref_id="CVE-2011-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0871.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:58.285-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:44.708-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:33.465-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" test_ref="oval:org.mitre.oval:tst:98078"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" test_ref="oval:org.mitre.oval:tst:98051"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" test_ref="oval:org.mitre.oval:tst:97976"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" test_ref="oval:org.mitre.oval:tst:97919"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" test_ref="oval:org.mitre.oval:tst:98022"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21482" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1208: glibc security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1208-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1208.html"/>
        <reference source="CESA" ref_id="CESA-2012:1208"/>
        <reference source="CVE" ref_id="CVE-2012-3480" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3480.html"/>
        <description>Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:15.164-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:43.986-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:32.460-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-devel is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:93938"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:94367"/>
          <criterion comment="glibc is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:94274"/>
          <criterion comment="nscd is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:94209"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:94471"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:94347"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.80.el6_3.5" test_ref="oval:org.mitre.oval:tst:93965"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21480" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1283: openjpeg security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openjpeg</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1283-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1283.html"/>
        <reference source="CESA" ref_id="CESA-2012:1283"/>
        <reference source="CVE" ref_id="CVE-2012-3535" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3535.html"/>
        <description>Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted JPEG2000 file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:08.668-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:43.913-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:32.360-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openjpeg-libs is earlier than 0:1.3-9.el6_3" test_ref="oval:org.mitre.oval:tst:94265"/>
          <criterion comment="openjpeg is earlier than 0:1.3-9.el6_3" test_ref="oval:org.mitre.oval:tst:94005"/>
          <criterion comment="openjpeg-devel is earlier than 0:1.3-9.el6_3" test_ref="oval:org.mitre.oval:tst:94244"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21479" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0180: pango security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>evolution28-pango</product>
          <product>pango</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0180-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0180.html"/>
        <reference source="CVE" ref_id="CVE-2011-0020" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0020.html"/>
        <description>Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:38.850-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:43.846-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:32.267-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21479 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:23.943-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:06.479-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pango-devel is earlier than 0:1.14.9-8.el5_6.2" test_ref="oval:org.mitre.oval:tst:137637"/>
            <criterion comment="pango is earlier than 0:1.14.9-8.el5_6.2" test_ref="oval:org.mitre.oval:tst:137822"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="pango is earlier than 0:1.28.1-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:97231"/>
            <criterion comment="pango-debuginfo is earlier than 0:1.28.1-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:137760"/>
            <criterion comment="pango-devel is earlier than 0:1.28.1-3.el6_0.3" test_ref="oval:org.mitre.oval:tst:97059"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21478" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1268: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1268-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1268.html"/>
        <reference source="CESA" ref_id="CESA-2012:1268"/>
        <reference source="CVE" ref_id="CVE-2012-4244" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4244.html"/>
        <description>ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:17.683-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:43.768-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:32.157-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94463"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94441"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94630"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94707"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94697"/>
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94324"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21476" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0997: 389-ds-base security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0997-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0997.html"/>
        <reference source="CESA" ref_id="CESA-2012:0997"/>
        <reference source="CVE" ref_id="CVE-2012-2678" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2678.html"/>
        <reference source="CVE" ref_id="CVE-2012-2746" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2746.html"/>
        <description>389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log in plain text, which allows remote authenticated users to read the password.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:46.627-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:43.670-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:32.040-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="389-ds-base is earlier than 0:1.2.10.2-18.el6_3" test_ref="oval:org.mitre.oval:tst:94041"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.10.2-18.el6_3" test_ref="oval:org.mitre.oval:tst:93480"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.10.2-18.el6_3" test_ref="oval:org.mitre.oval:tst:93224"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21473" version="120" class="patch">
      <metadata>
        <title>RHSA-2012:0743: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0743-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0743.html"/>
        <reference source="CESA" ref_id="CESA-2012:0743"/>
        <reference source="CVE" ref_id="CVE-2012-0044" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0044.html"/>
        <reference source="CVE" ref_id="CVE-2012-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1179.html"/>
        <reference source="CVE" ref_id="CVE-2012-2119" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2119.html"/>
        <reference source="CVE" ref_id="CVE-2012-2121" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2121.html"/>
        <reference source="CVE" ref_id="CVE-2012-2123" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2123.html"/>
        <reference source="CVE" ref_id="CVE-2012-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2136.html"/>
        <reference source="CVE" ref_id="CVE-2012-2137" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2137.html"/>
        <reference source="CVE" ref_id="CVE-2012-2372" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2372.html"/>
        <reference source="CVE" ref_id="CVE-2012-2373" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2373.html"/>
        <description>The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly use the Page Middle Directory (PMD), which allows local users to cause a denial of service (panic) via a crafted application that triggers a race condition.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:29.754-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:43.239-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:31.419-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93847"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93651"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:92933"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93499"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93487"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93514"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93623"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93785"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93437"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93709"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93379"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.23.1.el6" test_ref="oval:org.mitre.oval:tst:93645"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21461" version="185" class="patch">
      <metadata>
        <title>RHSA-2012:0467: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0467-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0467.html"/>
        <reference source="CESA" ref_id="CESA-2012:0467"/>
        <reference source="CVE" ref_id="CVE-2012-1126" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1126.html"/>
        <reference source="CVE" ref_id="CVE-2012-1127" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1127.html"/>
        <reference source="CVE" ref_id="CVE-2012-1130" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1130.html"/>
        <reference source="CVE" ref_id="CVE-2012-1131" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1131.html"/>
        <reference source="CVE" ref_id="CVE-2012-1132" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1132.html"/>
        <reference source="CVE" ref_id="CVE-2012-1134" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1134.html"/>
        <reference source="CVE" ref_id="CVE-2012-1136" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1136.html"/>
        <reference source="CVE" ref_id="CVE-2012-1137" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1137.html"/>
        <reference source="CVE" ref_id="CVE-2012-1139" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1139.html"/>
        <reference source="CVE" ref_id="CVE-2012-1140" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1140.html"/>
        <reference source="CVE" ref_id="CVE-2012-1141" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1141.html"/>
        <reference source="CVE" ref_id="CVE-2012-1142" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1142.html"/>
        <reference source="CVE" ref_id="CVE-2012-1143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1143.html"/>
        <reference source="CVE" ref_id="CVE-2012-1144" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1144.html"/>
        <description>FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:03.305-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:42.752-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:30.533-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:92695"/>
            <criterion comment="freetype is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:93043"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-31.el5_8.1" test_ref="oval:org.mitre.oval:tst:93350"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:93242"/>
            <criterion comment="freetype is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:93348"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_2.9" test_ref="oval:org.mitre.oval:tst:93238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21459" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0393: glibc security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0393-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0393.html"/>
        <reference source="CESA" ref_id="CESA-2012:0393"/>
        <reference source="CVE" ref_id="CVE-2012-0864" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0864.html"/>
        <description>Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:15.980-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:42.586-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:30.274-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-devel is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:92834"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:93013"/>
          <criterion comment="glibc is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:93071"/>
          <criterion comment="nscd is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:92200"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:93051"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:92846"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.47.el6_2.9" test_ref="oval:org.mitre.oval:tst:92701"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21458" version="55" class="patch">
      <metadata>
        <title>RHSA-2011:0009: evince security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>evince</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0009-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0009.html"/>
        <reference source="CVE" ref_id="CVE-2010-2640" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2640.html"/>
        <reference source="CVE" ref_id="CVE-2010-2641" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2641.html"/>
        <reference source="CVE" ref_id="CVE-2010-2642" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2642.html"/>
        <reference source="CVE" ref_id="CVE-2010-2643" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2643.html"/>
        <description>Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:34.184-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:42.476-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:30.114-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="evince is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:97020"/>
          <criterion comment="evince-libs is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:97050"/>
          <criterion comment="evince-devel is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:96824"/>
          <criterion comment="evince-dvi is earlier than 0:2.28.2-14.el6_0.1" test_ref="oval:org.mitre.oval:tst:96245"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21454" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0862: Red Hat Enterprise Linux 6 kernel security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0862-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0862.html"/>
        <reference source="CESA" ref_id="CESA-2012:0862"/>
        <reference source="CVE" ref_id="CVE-2011-1083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1083.html"/>
        <reference source="CVE" ref_id="CVE-2011-4131" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4131.html"/>
        <description>The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:33.543-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:42.201-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:29.741-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:93525"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:93063"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:93942"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:93920"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:93650"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:93751"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:93728"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:93644"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:94025"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:94006"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:93822"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.el6" test_ref="oval:org.mitre.oval:tst:93892"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21452" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:1391: httpd security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1391-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1391.html"/>
        <reference source="CVE" ref_id="CVE-2011-3348" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3348.html"/>
        <reference source="CVE" ref_id="CVE-2011-3368" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3368.html"/>
        <description>The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an initial @ (at sign) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:05.307-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:42.117-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:29.617-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="httpd-devel is earlier than 0:2.2.15-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:98515"/>
          <criterion comment="httpd-tools is earlier than 0:2.2.15-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:98619"/>
          <criterion comment="httpd-manual is earlier than 0:2.2.15-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:98546"/>
          <criterion comment="mod_ssl is earlier than 0:2.2.15-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:98638"/>
          <criterion comment="httpd is earlier than 0:2.2.15-9.el6_1.3" test_ref="oval:org.mitre.oval:tst:98542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21451" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:0481: kernel security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0481-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0481.html"/>
        <reference source="CESA" ref_id="CESA-2012:0481"/>
        <reference source="CVE" ref_id="CVE-2012-0879" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0879.html"/>
        <reference source="CVE" ref_id="CVE-2012-1090" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1090.html"/>
        <reference source="CVE" ref_id="CVE-2012-1097" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1097.html"/>
        <description>The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:11.999-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:41.992-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:29.394-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:92715"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:92566"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:93160"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:93356"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:93235"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:92912"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:93364"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:92954"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:92760"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:93175"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:93381"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.13.1.el6" test_ref="oval:org.mitre.oval:tst:93123"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21447" version="122" class="patch">
      <metadata>
        <title>RHSA-2012:1238: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1238-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1238.html"/>
        <reference source="CVE" ref_id="CVE-2012-0551" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0551.html"/>
        <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
        <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
        <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
        <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
        <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
        <reference source="CVE" ref_id="CVE-2012-1721" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1721.html"/>
        <reference source="CVE" ref_id="CVE-2012-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1722.html"/>
        <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:18.757-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:41.796-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:29.107-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21447 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:15.504-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:05.524-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137558"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137867"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137154"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137790"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137919"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137905"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137773"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137674"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94510"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94179"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94059"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94517"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:93561"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94187"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94371"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21444" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0876: net-snmp security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>net-snmp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0876-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0876.html"/>
        <reference source="CESA" ref_id="CESA-2012:0876"/>
        <reference source="CVE" ref_id="CVE-2012-2141" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2141.html"/>
        <description>Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and snmpd crash) via an SNMP GET request for an entry not in the extension table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:56.759-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:41.721-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:29.000-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="net-snmp-python is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:93891"/>
          <criterion comment="net-snmp-devel is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:93573"/>
          <criterion comment="net-snmp is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:93743"/>
          <criterion comment="net-snmp-utils is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:93451"/>
          <criterion comment="net-snmp-perl is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:93778"/>
          <criterion comment="net-snmp-libs is earlier than 1:5.5-41.el6" test_ref="oval:org.mitre.oval:tst:93986"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21442" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1206: python-paste-script security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>python-paste-script</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1206-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1206.html"/>
        <reference source="CESA" ref_id="CESA-2012:1206"/>
        <reference source="CVE" ref_id="CVE-2012-0878" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0878.html"/>
        <description>Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:11.385-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:41.587-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:28.906-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="python-paste-script is earlier than 0:1.7.3-5.el6_3" test_ref="oval:org.mitre.oval:tst:94472"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21441" version="68" class="patch">
      <metadata>
        <title>RHSA-2011:0836: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0836-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0836.html"/>
        <reference source="CVE" ref_id="CVE-2010-3858" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3858.html"/>
        <reference source="CVE" ref_id="CVE-2011-1598" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1598.html"/>
        <reference source="CVE" ref_id="CVE-2011-1748" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1748.html"/>
        <reference source="CVE" ref_id="CVE-2011-1770" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1770.html"/>
        <reference source="CVE" ref_id="CVE-2011-1771" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1771.html"/>
        <description>The cifs_close function in fs/cifs/file.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (NULL pointer dereference and BUG) or possibly have unspecified other impact by setting the O_DIRECT flag during an attempt to open a file on a CIFS filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:52.789-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:41.444-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:28.683-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:97587"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:97253"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:97796"/>
          <criterion comment="perf is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:97685"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:97451"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:97104"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:97497"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:97849"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:97797"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:97838"/>
          <criterion comment="kernel is earlier than 0:2.6.32-131.2.1.el6" test_ref="oval:org.mitre.oval:tst:98007"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21435" version="174" class="patch">
      <metadata>
        <title>RHSA-2011:0885: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0885-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0885.html"/>
        <reference source="CVE" ref_id="CVE-2011-0083" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0083.html"/>
        <reference source="CVE" ref_id="CVE-2011-0085" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0085.html"/>
        <reference source="CVE" ref_id="CVE-2011-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2362.html"/>
        <reference source="CVE" ref_id="CVE-2011-2363" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2363.html"/>
        <reference source="CVE" ref_id="CVE-2011-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2364.html"/>
        <reference source="CVE" ref_id="CVE-2011-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2365.html"/>
        <reference source="CVE" ref_id="CVE-2011-2371" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2371.html"/>
        <reference source="CVE" ref_id="CVE-2011-2373" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2373.html"/>
        <reference source="CVE" ref_id="CVE-2011-2374" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2374.html"/>
        <reference source="CVE" ref_id="CVE-2011-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2375.html"/>
        <reference source="CVE" ref_id="CVE-2011-2376" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2376.html"/>
        <reference source="CVE" ref_id="CVE-2011-2377" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2377.html"/>
        <reference source="CVE" ref_id="CVE-2011-2605" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2605.html"/>
        <reference source="CESA-2011:0885" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-June/017621.html" ref_id="CESA-2011:0885-CentOS 5"/>
        <description>CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:59.136-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:41.118-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:28.283-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21435 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:15.027-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:03.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.18-2.el5_6" test_ref="oval:org.mitre.oval:tst:137844"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.18-2.el5_6" test_ref="oval:org.mitre.oval:tst:137543"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:3.6.18-1.el5_6" test_ref="oval:org.mitre.oval:tst:137886"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.6.18-1.el6_1" test_ref="oval:org.mitre.oval:tst:98128"/>
            <criterion comment="firefox-debuginfo is earlier than 0:3.6.18-1.el6_1" test_ref="oval:org.mitre.oval:tst:137646"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.18-2.el6_1" test_ref="oval:org.mitre.oval:tst:98209"/>
            <criterion comment="xulrunner-debuginfo is earlier than 0:1.9.2.18-2.el6_1" test_ref="oval:org.mitre.oval:tst:137812"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.18-2.el6_1" test_ref="oval:org.mitre.oval:tst:98234"/>
          </criteria>
        </criteria>
        <criteria comment="CentOS Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:3.6.18-1.el5.centos" test_ref="oval:org.mitre.oval:tst:137643"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21434" version="315" class="patch">
      <metadata>
        <title>RHSA-2012:1210: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1210-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1210.html"/>
        <reference source="CESA" ref_id="CESA-2012:1210"/>
        <reference source="CVE" ref_id="CVE-2012-1970" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1970.html"/>
        <reference source="CVE" ref_id="CVE-2012-1972" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1972.html"/>
        <reference source="CVE" ref_id="CVE-2012-1973" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1973.html"/>
        <reference source="CVE" ref_id="CVE-2012-1974" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1974.html"/>
        <reference source="CVE" ref_id="CVE-2012-1975" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1975.html"/>
        <reference source="CVE" ref_id="CVE-2012-1976" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1976.html"/>
        <reference source="CVE" ref_id="CVE-2012-3956" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3956.html"/>
        <reference source="CVE" ref_id="CVE-2012-3957" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3957.html"/>
        <reference source="CVE" ref_id="CVE-2012-3958" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3958.html"/>
        <reference source="CVE" ref_id="CVE-2012-3959" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3959.html"/>
        <reference source="CVE" ref_id="CVE-2012-3960" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3960.html"/>
        <reference source="CVE" ref_id="CVE-2012-3961" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3961.html"/>
        <reference source="CVE" ref_id="CVE-2012-3962" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3962.html"/>
        <reference source="CVE" ref_id="CVE-2012-3963" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3963.html"/>
        <reference source="CVE" ref_id="CVE-2012-3964" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3964.html"/>
        <reference source="CVE" ref_id="CVE-2012-3966" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3966.html"/>
        <reference source="CVE" ref_id="CVE-2012-3967" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3967.html"/>
        <reference source="CVE" ref_id="CVE-2012-3968" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3968.html"/>
        <reference source="CVE" ref_id="CVE-2012-3969" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3969.html"/>
        <reference source="CVE" ref_id="CVE-2012-3970" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3970.html"/>
        <reference source="CVE" ref_id="CVE-2012-3972" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3972.html"/>
        <reference source="CVE" ref_id="CVE-2012-3976" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3976.html"/>
        <reference source="CVE" ref_id="CVE-2012-3978" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3978.html"/>
        <reference source="CVE" ref_id="CVE-2012-3980" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3980.html"/>
        <description>The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:45.777-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:40.650-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:27.610-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-2.el5_8" test_ref="oval:org.mitre.oval:tst:94093"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-2.el5_8" test_ref="oval:org.mitre.oval:tst:93780"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.7-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94361"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.7-1.el5_8" test_ref="oval:org.mitre.oval:tst:93506"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:94434"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:94337"/>
            <criterion comment="firefox is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:94474"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94875"/>
            <criterion comment="xulrunner is earlier than 0:10.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94933"/>
            <criterion comment="firefox is earlier than 0:10.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21433" version="393" class="patch">
      <metadata>
        <title>RHSA-2011:0177: webkitgtk security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>webkitgtk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0177-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0177.html"/>
        <reference source="CVE" ref_id="CVE-2010-1780" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1780.html"/>
        <reference source="CVE" ref_id="CVE-2010-1782" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1782.html"/>
        <reference source="CVE" ref_id="CVE-2010-1783" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1783.html"/>
        <reference source="CVE" ref_id="CVE-2010-1784" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1784.html"/>
        <reference source="CVE" ref_id="CVE-2010-1785" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1785.html"/>
        <reference source="CVE" ref_id="CVE-2010-1786" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1786.html"/>
        <reference source="CVE" ref_id="CVE-2010-1787" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1787.html"/>
        <reference source="CVE" ref_id="CVE-2010-1788" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1788.html"/>
        <reference source="CVE" ref_id="CVE-2010-1790" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1790.html"/>
        <reference source="CVE" ref_id="CVE-2010-1792" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1792.html"/>
        <reference source="CVE" ref_id="CVE-2010-1793" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1793.html"/>
        <reference source="CVE" ref_id="CVE-2010-1807" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1807.html"/>
        <reference source="CVE" ref_id="CVE-2010-1812" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1812.html"/>
        <reference source="CVE" ref_id="CVE-2010-1814" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1814.html"/>
        <reference source="CVE" ref_id="CVE-2010-1815" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1815.html"/>
        <reference source="CVE" ref_id="CVE-2010-3113" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3113.html"/>
        <reference source="CVE" ref_id="CVE-2010-3114" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3114.html"/>
        <reference source="CVE" ref_id="CVE-2010-3115" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3115.html"/>
        <reference source="CVE" ref_id="CVE-2010-3116" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3116.html"/>
        <reference source="CVE" ref_id="CVE-2010-3119" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3119.html"/>
        <reference source="CVE" ref_id="CVE-2010-3255" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3255.html"/>
        <reference source="CVE" ref_id="CVE-2010-3257" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3257.html"/>
        <reference source="CVE" ref_id="CVE-2010-3259" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3259.html"/>
        <reference source="CVE" ref_id="CVE-2010-3812" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3812.html"/>
        <reference source="CVE" ref_id="CVE-2010-3813" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3813.html"/>
        <reference source="CVE" ref_id="CVE-2010-4197" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4197.html"/>
        <reference source="CVE" ref_id="CVE-2010-4198" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4198.html"/>
        <reference source="CVE" ref_id="CVE-2010-4204" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4204.html"/>
        <reference source="CVE" ref_id="CVE-2010-4206" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4206.html"/>
        <reference source="CVE" ref_id="CVE-2010-4577" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4577.html"/>
        <description>The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.552.343, webkitgtk before 1.2.6, and other products does not properly parse Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted local font, related to "Type Confusion."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:22.486-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:40.116-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:26.850-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="webkitgtk is earlier than 0:1.2.6-2.el6_0" test_ref="oval:org.mitre.oval:tst:96964"/>
          <criterion comment="webkitgtk-doc is earlier than 0:1.2.6-2.el6_0" test_ref="oval:org.mitre.oval:tst:97240"/>
          <criterion comment="webkitgtk-devel is earlier than 0:1.2.6-2.el6_0" test_ref="oval:org.mitre.oval:tst:96535"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21430" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0811: php-pecl-apc security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>php-pecl-apc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0811-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0811.html"/>
        <reference source="CESA" ref_id="CESA-2012:0811"/>
        <reference source="CVE" ref_id="CVE-2010-3294" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-3294.html"/>
        <description>Cross-site scripting (XSS) vulnerability in apc.php in the Alternative PHP Cache (APC) extension before 3.1.4 for PHP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:57.326-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:40.047-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:26.701-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php-pecl-apc is earlier than 0:3.1.9-2.el6" test_ref="oval:org.mitre.oval:tst:93634"/>
          <criterion comment="php-pecl-apc-devel is earlier than 0:3.1.9-2.el6" test_ref="oval:org.mitre.oval:tst:93869"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21427" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0710: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0710-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0710.html"/>
        <reference source="CESA" ref_id="CESA-2012:0710"/>
        <reference source="CVE" ref_id="CVE-2011-3101" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3101.html"/>
        <reference source="CVE" ref_id="CVE-2012-1937" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1937.html"/>
        <reference source="CVE" ref_id="CVE-2012-1938" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1938.html"/>
        <reference source="CVE" ref_id="CVE-2012-1939" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1939.html"/>
        <reference source="CVE" ref_id="CVE-2012-1940" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1940.html"/>
        <reference source="CVE" ref_id="CVE-2012-1941" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1941.html"/>
        <reference source="CVE" ref_id="CVE-2012-1944" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1944.html"/>
        <reference source="CVE" ref_id="CVE-2012-1945" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1945.html"/>
        <reference source="CVE" ref_id="CVE-2012-1946" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1946.html"/>
        <reference source="CVE" ref_id="CVE-2012-1947" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1947.html"/>
        <description>Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:58.231-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:39.634-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:26.382-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:93853"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:93792"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.5-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94639"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.5-1.el5_8" test_ref="oval:org.mitre.oval:tst:93625"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:93513"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:93267"/>
            <criterion comment="firefox is earlier than 0:10.0.5-1.el6_2" test_ref="oval:org.mitre.oval:tst:93805"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94740"/>
            <criterion comment="xulrunner is earlier than 0:10.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94967"/>
            <criterion comment="firefox is earlier than 0:10.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94601"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21426" version="7" class="patch">
      <metadata>
        <title>RHSA-2011:0373: firefox security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0373-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0373.html"/>
        <reference source="CESA-2011:0373" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017409.html" ref_id="CESA-2011:0373-CentOS 5"/>
        <description>Mozilla Firefox is an open source web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

This erratum blacklists a small number of HTTPS certificates. (BZ#689430)

All Firefox users should upgrade to these updated packages, which contain
a backported patch. After installing the update, Firefox must be restarted
for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:32.183-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:39.594-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:26.289-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21426 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.298-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:38.750-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21426 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:28.683-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:03.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.15-2.el5_6" test_ref="oval:org.mitre.oval:tst:137088"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.15-2.el5_6" test_ref="oval:org.mitre.oval:tst:137891"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner is earlier than 0:1.9.2.15-2.el6_0" test_ref="oval:org.mitre.oval:tst:97163"/>
            <criterion comment="xulrunner-debuginfo is earlier than 0:1.9.2.15-2.el6_0" test_ref="oval:org.mitre.oval:tst:137776"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.15-2.el6_0" test_ref="oval:org.mitre.oval:tst:97565"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21423" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0414: policycoreutils security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>policycoreutils</product>
          <product>selinux-policy</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0414-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0414.html"/>
        <reference source="CVE" ref_id="CVE-2011-1011" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1011.html"/>
        <description>The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new directory, which allows local users to replace or delete arbitrary /tmp files, and consequently cause a denial of service or possibly gain privileges, by running a setuid application that relies on /tmp, as demonstrated by the ksu application.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:03.754-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:39.497-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:26.149-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="selinux-policy-doc is earlier than 0:3.7.19-54.el6_0.5" test_ref="oval:org.mitre.oval:tst:96873"/>
          <criterion comment="selinux-policy-mls is earlier than 0:3.7.19-54.el6_0.5" test_ref="oval:org.mitre.oval:tst:97725"/>
          <criterion comment="selinux-policy-minimum is earlier than 0:3.7.19-54.el6_0.5" test_ref="oval:org.mitre.oval:tst:97625"/>
          <criterion comment="selinux-policy is earlier than 0:3.7.19-54.el6_0.5" test_ref="oval:org.mitre.oval:tst:97646"/>
          <criterion comment="selinux-policy-targeted is earlier than 0:3.7.19-54.el6_0.5" test_ref="oval:org.mitre.oval:tst:97211"/>
          <criterion comment="policycoreutils is earlier than 0:2.0.83-19.8.el6_0" test_ref="oval:org.mitre.oval:tst:97197"/>
          <criterion comment="policycoreutils-gui is earlier than 0:2.0.83-19.8.el6_0" test_ref="oval:org.mitre.oval:tst:97672"/>
          <criterion comment="policycoreutils-python is earlier than 0:2.0.83-19.8.el6_0" test_ref="oval:org.mitre.oval:tst:97752"/>
          <criterion comment="policycoreutils-sandbox is earlier than 0:2.0.83-19.8.el6_0" test_ref="oval:org.mitre.oval:tst:97815"/>
          <criterion comment="policycoreutils-newrole is earlier than 0:2.0.83-19.8.el6_0" test_ref="oval:org.mitre.oval:tst:97730"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21421" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0953: system-config-firewall security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>system-config-firewall</product>
          <product>system-config-printer</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0953-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0953.html"/>
        <reference source="CVE" ref_id="CVE-2011-2520" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2520.html"/>
        <description>fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:17.142-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:39.121-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:25.635-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="system-config-firewall-base is earlier than 0:1.2.27-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98159"/>
          <criterion comment="system-config-firewall is earlier than 0:1.2.27-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:97420"/>
          <criterion comment="system-config-firewall-tui is earlier than 0:1.2.27-3.el6_1.3" test_ref="oval:org.mitre.oval:tst:98305"/>
          <criterion comment="system-config-printer-libs is earlier than 0:1.1.16-17.el6_1.2" test_ref="oval:org.mitre.oval:tst:97880"/>
          <criterion comment="system-config-printer is earlier than 0:1.1.16-17.el6_1.2" test_ref="oval:org.mitre.oval:tst:97761"/>
          <criterion comment="system-config-printer-udev is earlier than 0:1.1.16-17.el6_1.2" test_ref="oval:org.mitre.oval:tst:98026"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21417" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0715: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0715-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0715.html"/>
        <reference source="CESA" ref_id="CESA-2012:0715"/>
        <reference source="CVE" ref_id="CVE-2011-3101" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3101.html"/>
        <reference source="CVE" ref_id="CVE-2012-1937" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1937.html"/>
        <reference source="CVE" ref_id="CVE-2012-1938" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1938.html"/>
        <reference source="CVE" ref_id="CVE-2012-1939" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1939.html"/>
        <reference source="CVE" ref_id="CVE-2012-1940" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1940.html"/>
        <reference source="CVE" ref_id="CVE-2012-1941" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1941.html"/>
        <reference source="CVE" ref_id="CVE-2012-1944" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1944.html"/>
        <reference source="CVE" ref_id="CVE-2012-1945" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1945.html"/>
        <reference source="CVE" ref_id="CVE-2012-1946" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1946.html"/>
        <reference source="CVE" ref_id="CVE-2012-1947" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1947.html"/>
        <description>Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:02.278-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:38.663-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:24.704-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el5_8" test_ref="oval:org.mitre.oval:tst:93540"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el5.centos" test_ref="oval:org.mitre.oval:tst:94763"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el6_2" test_ref="oval:org.mitre.oval:tst:93405"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.5-2.el6.centos" test_ref="oval:org.mitre.oval:tst:95039"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21411" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:1105: libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1105-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1105.html"/>
        <reference source="CVE" ref_id="CVE-2011-2501" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2501.html"/>
        <reference source="CVE" ref_id="CVE-2011-2690" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2690.html"/>
        <reference source="CVE" ref_id="CVE-2011-2692" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2692.html"/>
        <description>The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted PNG image that triggers the reading of uninitialized memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:01.802-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:37.875-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:23.210-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libpng-static is earlier than 2:1.2.46-1.el6_1" test_ref="oval:org.mitre.oval:tst:98301"/>
          <criterion comment="libpng-devel is earlier than 2:1.2.46-1.el6_1" test_ref="oval:org.mitre.oval:tst:97740"/>
          <criterion comment="libpng is earlier than 2:1.2.46-1.el6_1" test_ref="oval:org.mitre.oval:tst:98214"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21410" version="159" class="patch">
      <metadata>
        <title>RHSA-2012:0139: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0139-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0139.html"/>
        <reference source="CVE" ref_id="CVE-2011-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3563.html"/>
        <reference source="CVE" ref_id="CVE-2011-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3571.html"/>
        <reference source="CVE" ref_id="CVE-2011-5035" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5035.html"/>
        <reference source="CVE" ref_id="CVE-2012-0498" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0498.html"/>
        <reference source="CVE" ref_id="CVE-2012-0499" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0499.html"/>
        <reference source="CVE" ref_id="CVE-2012-0500" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0500.html"/>
        <reference source="CVE" ref_id="CVE-2012-0501" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0501.html"/>
        <reference source="CVE" ref_id="CVE-2012-0502" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0502.html"/>
        <reference source="CVE" ref_id="CVE-2012-0503" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0503.html"/>
        <reference source="CVE" ref_id="CVE-2012-0505" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0505.html"/>
        <reference source="CVE" ref_id="CVE-2012-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0506.html"/>
        <reference source="CVE" ref_id="CVE-2012-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0507.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.  NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:10.769-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:37.790-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:22.994-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:92776"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:92743"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:92712"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:92751"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:92754"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.31-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:93009"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21409" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0018: libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0018-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0018.html"/>
        <reference source="CESA" ref_id="CESA-2012:0018"/>
        <reference source="CVE" ref_id="CVE-2011-3905" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3905.html"/>
        <reference source="CVE" ref_id="CVE-2011-3919" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3919.html"/>
        <description>Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:00.626-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:37.702-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:22.861-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:92730"/>
          <criterion comment="libxml2-python is earlier than 0:2.7.6-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:92572"/>
          <criterion comment="libxml2 is earlier than 0:2.7.6-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:92378"/>
          <criterion comment="libxml2-static is earlier than 0:2.7.6-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:92788"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21408" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0136: libvorbis security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvorbis</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0136-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0136.html"/>
        <reference source="CESA" ref_id="CESA-2012:0136"/>
        <reference source="CVE" ref_id="CVE-2012-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0444.html"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted Ogg Vorbis file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:49.477-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:37.600-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:22.750-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libvorbis is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:92836"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:92918"/>
            <criterion comment="libvorbis-devel-docs is earlier than 1:1.2.3-4.el6_2.1" test_ref="oval:org.mitre.oval:tst:93040"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libvorbis is earlier than 1:1.1.2-3.el5_7.6" test_ref="oval:org.mitre.oval:tst:92964"/>
            <criterion comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_7.6" test_ref="oval:org.mitre.oval:tst:92940"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21407" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0434: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0434-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0434.html"/>
        <reference source="CVE" ref_id="CVE-2012-0773" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0773.html"/>
        <description>The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.223 on Solaris; Flash Player before 11.1.111.8 on Android 2.x and 3.x; and AIR before 3.2.0.2070 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:09.517-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:37.529-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:22.651-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.18-1.el5" test_ref="oval:org.mitre.oval:tst:92747"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.18-1.el6" test_ref="oval:org.mitre.oval:tst:92529"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21404" version="161" class="patch">
      <metadata>
        <title>RHSA-2012:0514: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0514-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0514.html"/>
        <reference source="CVE" ref_id="CVE-2011-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3563.html"/>
        <reference source="CVE" ref_id="CVE-2011-5035" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5035.html"/>
        <reference source="CVE" ref_id="CVE-2012-0497" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0497.html"/>
        <reference source="CVE" ref_id="CVE-2012-0498" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0498.html"/>
        <reference source="CVE" ref_id="CVE-2012-0499" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0499.html"/>
        <reference source="CVE" ref_id="CVE-2012-0500" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0500.html"/>
        <reference source="CVE" ref_id="CVE-2012-0501" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0501.html"/>
        <reference source="CVE" ref_id="CVE-2012-0502" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0502.html"/>
        <reference source="CVE" ref_id="CVE-2012-0503" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0503.html"/>
        <reference source="CVE" ref_id="CVE-2012-0505" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0505.html"/>
        <reference source="CVE" ref_id="CVE-2012-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0506.html"/>
        <reference source="CVE" ref_id="CVE-2012-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0507.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.  NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:44.821-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:37.214-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:22.230-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21404 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:28.964-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:02.570-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137818"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137749"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137383"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137901"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137870"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137766"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137830"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:136938"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:92894"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:92942"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:92824"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:93358"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:93089"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:92854"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" test_ref="oval:org.mitre.oval:tst:93104"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21403" version="159" class="patch">
      <metadata>
        <title>RHSA-2012:0734: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0734-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0734.html"/>
        <reference source="CVE" ref_id="CVE-2012-0551" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0551.html"/>
        <reference source="CVE" ref_id="CVE-2012-1711" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1711.html"/>
        <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
        <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
        <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
        <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
        <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
        <reference source="CVE" ref_id="CVE-2012-1721" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1721.html"/>
        <reference source="CVE" ref_id="CVE-2012-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1722.html"/>
        <reference source="CVE" ref_id="CVE-2012-1723" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1723.html"/>
        <reference source="CVE" ref_id="CVE-2012-1724" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1724.html"/>
        <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:33.986-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:36.952-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:21.876-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.33-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:93110"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.33-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:93441"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.33-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:93865"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.33-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:93718"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.33-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:93812"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.33-1jpp.1.el6_2" test_ref="oval:org.mitre.oval:tst:93383"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21398" version="161" class="patch">
      <metadata>
        <title>RHSA-2012:0508: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0508-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0508.html"/>
        <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html"/>
        <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html"/>
        <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html"/>
        <reference source="CVE" ref_id="CVE-2011-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3563.html"/>
        <reference source="CVE" ref_id="CVE-2012-0498" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0498.html"/>
        <reference source="CVE" ref_id="CVE-2012-0499" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0499.html"/>
        <reference source="CVE" ref_id="CVE-2012-0501" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0501.html"/>
        <reference source="CVE" ref_id="CVE-2012-0502" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0502.html"/>
        <reference source="CVE" ref_id="CVE-2012-0503" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0503.html"/>
        <reference source="CVE" ref_id="CVE-2012-0505" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0505.html"/>
        <reference source="CVE" ref_id="CVE-2012-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0506.html"/>
        <reference source="CVE" ref_id="CVE-2012-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0507.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.  NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:08.067-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:36.352-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:21.099-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21398 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:18.944-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:01.303-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137436"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137849"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137906"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137615"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137619"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137737"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137286"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.1-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:137936"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:92960"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:92763"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:92405"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:93293"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:92581"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:93370"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" test_ref="oval:org.mitre.oval:tst:93022"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21394" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0546: php security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0546-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0546.html"/>
        <reference source="CESA" ref_id="CESA-2012:0546"/>
        <reference source="CVE" ref_id="CVE-2012-1823" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1823.html"/>
        <description>sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:38.481-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:35.964-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:20.611-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-common is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93366"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93254"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93179"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93019"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93058"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:92904"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93158"/>
            <criterion comment="php is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93223"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93201"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:92622"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93285"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93111"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:92905"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93094"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:92648"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93274"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93181"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:92791"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-34.el5_8" test_ref="oval:org.mitre.oval:tst:93077"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93407"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93408"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93422"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93416"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93142"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93282"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93403"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93426"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93193"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:92979"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93197"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:92879"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93170"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93363"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93412"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93200"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93404"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93114"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:92988"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93207"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93368"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:92434"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93070"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93229"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:93157"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.8" test_ref="oval:org.mitre.oval:tst:92982"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21392" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0388: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0388-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0388.html"/>
        <reference source="CESA" ref_id="CESA-2012:0388"/>
        <reference source="CVE" ref_id="CVE-2012-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0451.html"/>
        <reference source="CVE" ref_id="CVE-2012-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0455.html"/>
        <reference source="CVE" ref_id="CVE-2012-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0456.html"/>
        <reference source="CVE" ref_id="CVE-2012-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0457.html"/>
        <reference source="CVE" ref_id="CVE-2012-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0458.html"/>
        <reference source="CVE" ref_id="CVE-2012-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0459.html"/>
        <reference source="CVE" ref_id="CVE-2012-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0460.html"/>
        <reference source="CVE" ref_id="CVE-2012-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0461.html"/>
        <reference source="CVE" ref_id="CVE-2012-0462" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0462.html"/>
        <reference source="CVE" ref_id="CVE-2012-0464" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0464.html"/>
        <description>Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:18.266-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:35.728-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:20.288-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:93120"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94945"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:93140"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94449"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21390" version="81" class="patch">
      <metadata>
        <title>RHSA-2012:0544: ImageMagick security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0544-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0544.html"/>
        <reference source="CESA" ref_id="CESA-2012:0544"/>
        <reference source="CVE" ref_id="CVE-2010-4167" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4167.html"/>
        <reference source="CVE" ref_id="CVE-2012-0247" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0247.html"/>
        <reference source="CVE" ref_id="CVE-2012-0248" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0248.html"/>
        <reference source="CVE" ref_id="CVE-2012-0259" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0259.html"/>
        <reference source="CVE" ref_id="CVE-2012-0260" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0260.html"/>
        <reference source="CVE" ref_id="CVE-2012-1798" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1798.html"/>
        <description>The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:35.573-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:35.375-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:19.785-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ImageMagick-doc is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:93316"/>
          <criterion comment="ImageMagick-perl is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:92812"/>
          <criterion comment="ImageMagick-devel is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:93295"/>
          <criterion comment="ImageMagick-c++-devel is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:92705"/>
          <criterion comment="ImageMagick-c++ is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:93393"/>
          <criterion comment="ImageMagick is earlier than 0:6.5.4.7-6.el6_2" test_ref="oval:org.mitre.oval:tst:93284"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21389" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:0744: python security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0744-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0744.html"/>
        <reference source="CESA" ref_id="CESA-2012:0744"/>
        <reference source="CVE" ref_id="CVE-2011-4940" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4940.html"/>
        <reference source="CVE" ref_id="CVE-2011-4944" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4944.html"/>
        <reference source="CVE" ref_id="CVE-2012-0845" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0845.html"/>
        <reference source="CVE" ref_id="CVE-2012-1150" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1150.html"/>
        <description>Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:01.736-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:35.230-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:19.619-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="python-devel is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:93026"/>
          <criterion comment="python-test is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:93602"/>
          <criterion comment="tkinter is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:93765"/>
          <criterion comment="python is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:93801"/>
          <criterion comment="python-tools is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:93677"/>
          <criterion comment="python-libs is earlier than 0:2.6.6-29.el6_2.2" test_ref="oval:org.mitre.oval:tst:93570"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21388" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0699: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0699-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0699.html"/>
        <reference source="CESA" ref_id="CESA-2012:0699"/>
        <reference source="CVE" ref_id="CVE-2012-2333" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2333.html"/>
        <description>Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:42.503-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:35.120-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:19.498-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:93493"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:93567"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.4" test_ref="oval:org.mitre.oval:tst:93399"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:93414"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:92594"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:92832"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.5" test_ref="oval:org.mitre.oval:tst:93576"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21387" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0813: 389-ds-base security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0813-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0813.html"/>
        <reference source="CESA" ref_id="CESA-2012:0813"/>
        <reference source="CVE" ref_id="CVE-2012-0833" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0833.html"/>
        <description>The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups, which allows remote authenticated LDAP users with a certificate group to cause a denial of service (infinite loop and CPU consumption) by binding to the server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:32.696-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:35.038-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:19.396-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="389-ds-base is earlier than 0:1.2.10.2-15.el6" test_ref="oval:org.mitre.oval:tst:93978"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.10.2-15.el6" test_ref="oval:org.mitre.oval:tst:93848"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.10.2-15.el6" test_ref="oval:org.mitre.oval:tst:93907"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21385" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1418: kdelibs security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1418-00" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1418.html"/>
        <reference source="CESA" ref_id="CESA-2012:1418"/>
        <reference source="CVE" ref_id="CVE-2012-4512" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4512.html"/>
        <reference source="CVE" ref_id="CVE-2012-4513" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4513.html"/>
        <description>khtml/imload/scaledimageplane.h in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via large canvas dimensions, which leads to an unexpected sign extension and a heap-based buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:28.641-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:34.888-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:19.199-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kdelibs-devel is earlier than 6:4.3.4-19.el6" test_ref="oval:org.mitre.oval:tst:94687"/>
          <criterion comment="kdelibs-common is earlier than 6:4.3.4-19.el6" test_ref="oval:org.mitre.oval:tst:94890"/>
          <criterion comment="kdelibs is earlier than 6:4.3.4-19.el6" test_ref="oval:org.mitre.oval:tst:94853"/>
          <criterion comment="kdelibs-apidocs is earlier than 6:4.3.4-19.el6" test_ref="oval:org.mitre.oval:tst:94632"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21380" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0599: sudo security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0599-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0599.html"/>
        <reference source="CVE" ref_id="CVE-2011-0010" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0010.html"/>
        <description>check.c in sudo 1.7.x before 1.7.4p5, when a Runas group is configured, does not require a password for command execution that involves a gid change but no uid change, which allows local users to bypass an intended authentication requirement via the -g option to a sudo command.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:08.922-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:34.357-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:18.469-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="sudo is earlier than 0:1.7.4p5-5.el6" test_ref="oval:org.mitre.oval:tst:97924"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21376" version="83" class="patch">
      <metadata>
        <title>RHSA-2012:0722: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0722-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0722.html"/>
        <reference source="CVE" ref_id="CVE-2012-2034" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2034.html"/>
        <reference source="CVE" ref_id="CVE-2012-2035" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2035.html"/>
        <reference source="CVE" ref_id="CVE-2012-2036" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2036.html"/>
        <reference source="CVE" ref_id="CVE-2012-2037" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2037.html"/>
        <reference source="CVE" ref_id="CVE-2012-2038" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2038.html"/>
        <reference source="CVE" ref_id="CVE-2012-2039" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2039.html"/>
        <description>Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:21.389-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:34.120-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:18.125-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21376 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:06.126-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:01:00.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.20-1.el5" test_ref="oval:org.mitre.oval:tst:137696"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.20-1.el6" test_ref="oval:org.mitre.oval:tst:93641"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21375" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1549: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1549-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1549.html"/>
        <reference source="CESA" ref_id="CESA-2012:1549"/>
        <reference source="CVE" ref_id="CVE-2012-5688" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5688.html"/>
        <description>ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:53.578-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:34.044-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:18.025-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:94354"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:94526"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:94717"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:94704"/>
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:94544"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.6" test_ref="oval:org.mitre.oval:tst:94467"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21373" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:1590: libtiff security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1590-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1590.html"/>
        <reference source="CESA" ref_id="CESA-2012:1590"/>
        <reference source="CVE" ref_id="CVE-2012-3401" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3401.html"/>
        <reference source="CVE" ref_id="CVE-2012-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4447.html"/>
        <reference source="CVE" ref_id="CVE-2012-4564" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4564.html"/>
        <reference source="CVE" ref_id="CVE-2012-5581" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5581.html"/>
        <description>Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DOTRANGE tag in a TIFF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:26.906-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.752-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:17.502-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:94475"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-18.el5_8" test_ref="oval:org.mitre.oval:tst:94221"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:94950"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:94836"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-9.el6_3" test_ref="oval:org.mitre.oval:tst:94861"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21372" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0571: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0571-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0571.html"/>
        <reference source="CESA" ref_id="CESA-2012:0571"/>
        <reference source="CVE" ref_id="CVE-2011-4086" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4086.html"/>
        <reference source="CVE" ref_id="CVE-2012-1601" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1601.html"/>
        <description>The KVM implementation in the Linux kernel before 3.3.6 allows host OS users to cause a denial of service (NULL pointer dereference and host OS crash) by making a KVM_CREATE_IRQCHIP ioctl call after a virtual CPU already exists.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:35.162-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.668-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:17.382-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:93053"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:93410"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:93442"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:93062"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:92805"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:92811"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:93444"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:93450"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:93176"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:93231"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:93178"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.17.1.el6" test_ref="oval:org.mitre.oval:tst:92992"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21369" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1131: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1131-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1131.html"/>
        <reference source="CESA" ref_id="CESA-2012:1131"/>
        <reference source="CVE" ref_id="CVE-2012-1013" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1013.html"/>
        <reference source="CVE" ref_id="CVE-2012-1015" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1015.html"/>
        <description>The kdc_handle_protected_negotiation function in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x, 1.9.x before 1.9.5, and 1.10.x before 1.10.3 attempts to calculate a checksum before verifying that the key type is appropriate for a checksum, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized pointer free, heap memory corruption, and daemon crash) via a crafted AS-REQ request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:24.682-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.333-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:16.905-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-server-ldap is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:93747"/>
          <criterion comment="krb5-devel is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:93972"/>
          <criterion comment="krb5-workstation is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:94184"/>
          <criterion comment="krb5-libs is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:93882"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:94171"/>
          <criterion comment="krb5-server is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:94127"/>
          <criterion comment="krb5 is earlier than 0:1.9-33.el6_3.2" test_ref="oval:org.mitre.oval:tst:94197"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21367" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1261: dbus security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>dbus</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1261-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1261.html"/>
        <reference source="CESA" ref_id="CESA-2012:1261"/>
        <reference source="CVE" ref_id="CVE-2012-3524" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3524.html"/>
        <description>libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable.  NOTE: libdbus maintainers state that this is a vulnerability in the applications that do not cleanse environment variables, not in libdbus itself: "we do not support use of libdbus in setuid binaries that do not sanitize their environment before their first call into libdbus."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:14.034-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.258-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:16.790-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dbus-devel is earlier than 1:1.2.24-7.el6_3" test_ref="oval:org.mitre.oval:tst:94552"/>
          <criterion comment="dbus is earlier than 1:1.2.24-7.el6_3" test_ref="oval:org.mitre.oval:tst:94520"/>
          <criterion comment="dbus-x11 is earlier than 1:1.2.24-7.el6_3" test_ref="oval:org.mitre.oval:tst:94521"/>
          <criterion comment="dbus-libs is earlier than 1:1.2.24-7.el6_3" test_ref="oval:org.mitre.oval:tst:94488"/>
          <criterion comment="dbus-doc is earlier than 1:1.2.24-7.el6_3" test_ref="oval:org.mitre.oval:tst:94496"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21366" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0518: openssl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
          <product>openssl097a</product>
          <product>openssl098e</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0518-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0518.html"/>
        <reference source="CESA" ref_id="CESA-2012:0518"/>
        <reference source="CVE" ref_id="CVE-2012-2110" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2110.html"/>
        <description>The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:55.683-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:33.157-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:16.651-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:92802"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:93327"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.3" test_ref="oval:org.mitre.oval:tst:93345"/>
            <criterion comment="openssl097a is earlier than 0:0.9.7a-11.el5_8.2" test_ref="oval:org.mitre.oval:tst:93396"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 and Centos 6 section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:93126"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:92825"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:93186"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.4" test_ref="oval:org.mitre.oval:tst:93154"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criterion comment="openssl098e is earlier than 0:0.9.8e-17.el6.centos.2" test_ref="oval:org.mitre.oval:tst:94870"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="openssl098e is earlier than 0:0.9.8e-17.el6_2.2" test_ref="oval:org.mitre.oval:tst:93183"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21356" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1263: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1263-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1263.html"/>
        <reference source="CESA" ref_id="CESA-2012:1263"/>
        <reference source="CVE" ref_id="CVE-2012-3488" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3488.html"/>
        <reference source="CVE" ref_id="CVE-2012-3489" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3489.html"/>
        <description>The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing error, via an XML value that refers to (1) a DTD or (2) an entity, related to an XML External Entity (aka XXE) issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:21.958-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:31.369-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:15.566-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94123"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94376"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94506"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94217"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94038"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94537"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:93867"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94530"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94296"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94264"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94344"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.13-1.el5_8" test_ref="oval:org.mitre.oval:tst:94212"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94457"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94531"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:93983"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94490"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94445"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94185"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:93982"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94410"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:94332"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.13-1.el6_3" test_ref="oval:org.mitre.oval:tst:93946"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21354" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:1223: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1223-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1223.html"/>
        <reference source="CESA" ref_id="CESA-2012:1223"/>
        <reference source="CVE" ref_id="CVE-2012-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0547.html"/>
        <reference source="CVE" ref_id="CVE-2012-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1682.html"/>
        <reference source="CVE" ref_id="CVE-2012-3136" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3136.html"/>
        <reference source="CVE" ref_id="CVE-2012-4681" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4681.html"/>
        <description>Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) using com.sun.beans.finder.ClassFinder.findClass and leveraging an exception with the forName method to access restricted classes from arbitrary packages such as sun.awt.SunToolkit, then (2) using "reflection with a trusted immediate caller" to leverage the getField method to access and modify private fields, as exploited in the wild in August 2012 using Gondzz.class and Gondvv.class.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:07.359-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:31.236-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:15.422-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.5-2.2.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94482"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.5-2.2.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94393"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.5-2.2.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94382"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.5-2.2.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94070"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.5-2.2.1.el6_3.3" test_ref="oval:org.mitre.oval:tst:94160"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21349" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0317: libpng security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libpng</product>
          <product>libpng10</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0317-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0317.html"/>
        <reference source="CESA" ref_id="CESA-2012:0317"/>
        <reference source="CVE" ref_id="CVE-2011-3026" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3026.html"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:42.171-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:19.176-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:15.239-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-static is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:93076"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:93067"/>
            <criterion comment="libpng is earlier than 2:1.2.46-2.el6_2" test_ref="oval:org.mitre.oval:tst:92956"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-15.el5_7" test_ref="oval:org.mitre.oval:tst:92474"/>
            <criterion comment="libpng is earlier than 2:1.2.10-15.el5_7" test_ref="oval:org.mitre.oval:tst:92710"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21345" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0465: samba security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0465-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0465.html"/>
        <reference source="CESA" ref_id="CESA-2012:0465"/>
        <reference source="CVE" ref_id="CVE-2012-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1182.html"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:01.730-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:18.398-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:14.138-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-client is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:93248"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:92770"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:93185"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:93128"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:93259"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.39.el5_8" test_ref="oval:org.mitre.oval:tst:93323"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-client is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93137"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93336"/>
            <criterion comment="samba is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93134"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93255"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93167"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93346"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:92981"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93112"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93262"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93311"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:93148"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-115.el6_2" test_ref="oval:org.mitre.oval:tst:92630"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21344" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0841: abrt, libreport, btparser, and python-meh security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>abrt</product>
          <product>btparser</product>
          <product>libreport</product>
          <product>python-meh</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0841-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0841.html"/>
        <reference source="CESA" ref_id="CESA-2012:0841"/>
        <reference source="CVE" ref_id="CVE-2011-4088" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4088.html"/>
        <reference source="CVE" ref_id="CVE-2012-1106" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1106.html"/>
        <description>The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:20.432-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:18.191-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:13.786-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 and Centos 6 section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="python-meh is earlier than 0:0.12.1-3.el6" test_ref="oval:org.mitre.oval:tst:93596"/>
            <criterion comment="btparser-python is earlier than 0:0.16-3.el6" test_ref="oval:org.mitre.oval:tst:93999"/>
            <criterion comment="btparser is earlier than 0:0.16-3.el6" test_ref="oval:org.mitre.oval:tst:93006"/>
            <criterion comment="btparser-devel is earlier than 0:0.16-3.el6" test_ref="oval:org.mitre.oval:tst:93819"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="abrt-desktop is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:94748"/>
            <criterion comment="abrt-gui is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:95081"/>
            <criterion comment="abrt is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:95051"/>
            <criterion comment="abrt-devel is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:94985"/>
            <criterion comment="abrt-addon-kerneloops is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:94696"/>
            <criterion comment="abrt-tui is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:94591"/>
            <criterion comment="abrt-addon-vmcore is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:94995"/>
            <criterion comment="abrt-addon-ccpp is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:94464"/>
            <criterion comment="abrt-addon-python is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:94854"/>
            <criterion comment="abrt-libs is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:94830"/>
            <criterion comment="abrt-cli is earlier than 0:2.0.8-6.el6.centos" test_ref="oval:org.mitre.oval:tst:94860"/>
            <criterion comment="libreport-plugin-mailx is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:95032"/>
            <criterion comment="libreport-plugin-rhtsupport is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:94964"/>
            <criterion comment="libreport-gtk-devel is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:94831"/>
            <criterion comment="libreport-python is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:94699"/>
            <criterion comment="libreport-cli is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:94981"/>
            <criterion comment="libreport is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:94969"/>
            <criterion comment="libreport-plugin-reportuploader is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:94931"/>
            <criterion comment="libreport-newt is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:94677"/>
            <criterion comment="libreport-gtk is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:95073"/>
            <criterion comment="libreport-plugin-kerneloops is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:95024"/>
            <criterion comment="libreport-devel is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:95095"/>
            <criterion comment="libreport-plugin-logger is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:94549"/>
            <criterion comment="libreport-plugin-bugzilla is earlier than 0:2.0.9-5.el6.centos" test_ref="oval:org.mitre.oval:tst:95057"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="abrt-desktop is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93035"/>
            <criterion comment="abrt-gui is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93893"/>
            <criterion comment="abrt is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93883"/>
            <criterion comment="abrt-devel is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93838"/>
            <criterion comment="abrt-addon-kerneloops is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93894"/>
            <criterion comment="abrt-tui is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93784"/>
            <criterion comment="abrt-addon-vmcore is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93933"/>
            <criterion comment="abrt-addon-ccpp is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93626"/>
            <criterion comment="abrt-addon-python is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93799"/>
            <criterion comment="abrt-libs is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93854"/>
            <criterion comment="abrt-cli is earlier than 0:2.0.8-6.el6" test_ref="oval:org.mitre.oval:tst:93380"/>
            <criterion comment="libreport-plugin-mailx is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93162"/>
            <criterion comment="libreport-plugin-rhtsupport is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93910"/>
            <criterion comment="libreport-gtk-devel is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93856"/>
            <criterion comment="libreport-python is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93685"/>
            <criterion comment="libreport-cli is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93617"/>
            <criterion comment="libreport is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93793"/>
            <criterion comment="libreport-plugin-reportuploader is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93928"/>
            <criterion comment="libreport-newt is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93813"/>
            <criterion comment="libreport-gtk is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93949"/>
            <criterion comment="libreport-plugin-kerneloops is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93527"/>
            <criterion comment="libreport-devel is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93326"/>
            <criterion comment="libreport-plugin-logger is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93967"/>
            <criterion comment="libreport-plugin-bugzilla is earlier than 0:2.0.9-5.el6" test_ref="oval:org.mitre.oval:tst:93667"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21341" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1361: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1361-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1361.html"/>
        <reference source="CESA" ref_id="CESA-2012:1361"/>
        <reference source="CVE" ref_id="CVE-2012-4193" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4193.html"/>
        <description>Mozilla Firefox before 16.0.1, Firefox ESR 10.x before 10.0.9, Thunderbird before 16.0.1, Thunderbird ESR 10.x before 10.0.9, and SeaMonkey before 2.13.1 omit a security check in the defaultValue function during the unwrapping of security wrappers, which allows remote attackers to bypass the Same Origin Policy and read the properties of a Location object, or execute arbitrary JavaScript code, via a crafted web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:17.563-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:17.941-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:13.493-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:94320"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.el5_8" test_ref="oval:org.mitre.oval:tst:94600"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:94757"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.el6_3" test_ref="oval:org.mitre.oval:tst:94756"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.8-2.el6.centos" test_ref="oval:org.mitre.oval:tst:94746"/>
            <criterion comment="xulrunner is earlier than 0:10.0.8-2.el6.centos" test_ref="oval:org.mitre.oval:tst:95038"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21340" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0135: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0135-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0135.html"/>
        <reference source="CESA" ref_id="CESA-2012:0135"/>
        <reference source="CVE" ref_id="CVE-2011-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3563.html"/>
        <reference source="CVE" ref_id="CVE-2011-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3571.html"/>
        <reference source="CVE" ref_id="CVE-2011-5035" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-5035.html"/>
        <reference source="CVE" ref_id="CVE-2012-0497" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0497.html"/>
        <reference source="CVE" ref_id="CVE-2012-0501" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0501.html"/>
        <reference source="CVE" ref_id="CVE-2012-0502" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0502.html"/>
        <reference source="CVE" ref_id="CVE-2012-0503" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0503.html"/>
        <reference source="CVE" ref_id="CVE-2012-0505" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0505.html"/>
        <reference source="CVE" ref_id="CVE-2012-0506" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0506.html"/>
        <reference source="CVE" ref_id="CVE-2012-0507" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0507.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency.  NOTE: the previous information was obtained from the February 2012 Oracle CPU. Oracle has not commented on claims from a downstream vendor and third party researchers that this issue occurs because the AtomicReferenceArray class implementation does not ensure that the array is of the Object[] type, which allows attackers to cause a denial of service (JVM crash) or bypass Java sandbox restrictions.  NOTE: this issue was originally mapped to CVE-2011-3571, but that identifier was already assigned to a different issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:10.306-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:17.637-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:13.218-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:92814"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:92973"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:92616"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:92953"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.43.1.10.6.el6_2" test_ref="oval:org.mitre.oval:tst:92823"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21339" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:0678: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0678-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0678.html"/>
        <reference source="CESA" ref_id="CESA-2012:0678"/>
        <reference source="CVE" ref_id="CVE-2012-0866" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0866.html"/>
        <reference source="CVE" ref_id="CVE-2012-0867" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0867.html"/>
        <reference source="CVE" ref_id="CVE-2012-0868" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0868.html"/>
        <description>CRLF injection vulnerability in pg_dump in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows user-assisted remote attackers to execute arbitrary SQL commands via a crafted file containing object names with newlines, which are inserted into an SQL script that is used when the database is restored.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:47.575-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:17.457-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:13.023-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93559"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93002"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93322"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93206"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93528"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93478"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93564"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93331"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93300"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:92586"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93333"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:93279"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93417"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93230"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93475"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93387"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93469"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93353"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93549"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93419"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93268"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.11-1.el6_2" test_ref="oval:org.mitre.oval:tst:93310"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21336" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0019: php53 and php security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0019-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0019.html"/>
        <reference source="CESA" ref_id="CESA-2012:0019"/>
        <reference source="CVE" ref_id="CVE-2011-4566" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4566.html"/>
        <reference source="CVE" ref_id="CVE-2011-4885" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4885.html"/>
        <description>PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:45.594-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:17.070-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:12.594-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92318"/>
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92528"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92709"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92724"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92585"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92698"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92692"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92723"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92728"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92722"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92531"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92693"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92746"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92757"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92638"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92396"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92257"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92601"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92280"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92631"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92790"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92359"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92120"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92442"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92417"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.5" test_ref="oval:org.mitre.oval:tst:92520"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92759"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92025"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92677"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92707"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92153"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92372"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92382"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92756"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92607"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92604"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92681"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92401"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92673"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92628"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92469"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92432"/>
            <criterion comment="php53-intl is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92290"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92656"/>
            <criterion comment="php53 is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92697"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92348"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.5" test_ref="oval:org.mitre.oval:tst:92735"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21334" version="83" class="patch">
      <metadata>
        <title>RHSA-2012:1245: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1245-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1245.html"/>
        <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
        <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
        <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
        <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
        <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
        <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:11.634-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:16.803-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:12.286-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21334 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:27.021-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:59.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137922"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137620"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137738"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137917"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137002"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137929"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137504"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.14.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137450"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94282"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94362"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94293"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94256"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:93911"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94298"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.14.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94470"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21333" version="159" class="patch">
      <metadata>
        <title>RHSA-2012:0515: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0515-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0515.html"/>
        <reference source="CESA" ref_id="CESA-2012:0515"/>
        <reference source="CVE" ref_id="CVE-2011-3062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3062.html"/>
        <reference source="CVE" ref_id="CVE-2012-0467" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0467.html"/>
        <reference source="CVE" ref_id="CVE-2012-0468" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0468.html"/>
        <reference source="CVE" ref_id="CVE-2012-0469" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0469.html"/>
        <reference source="CVE" ref_id="CVE-2012-0470" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0470.html"/>
        <reference source="CVE" ref_id="CVE-2012-0471" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0471.html"/>
        <reference source="CVE" ref_id="CVE-2012-0472" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0472.html"/>
        <reference source="CVE" ref_id="CVE-2012-0473" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0473.html"/>
        <reference source="CVE" ref_id="CVE-2012-0474" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0474.html"/>
        <reference source="CVE" ref_id="CVE-2012-0477" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0477.html"/>
        <reference source="CVE" ref_id="CVE-2012-0478" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0478.html"/>
        <reference source="CVE" ref_id="CVE-2012-0479" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0479.html"/>
        <description>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:17.498-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:16.413-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:11.878-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:93130"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:92785"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.4-1.el5.centos" test_ref="oval:org.mitre.oval:tst:95029"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:93351"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:93270"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:92884"/>
            <criterion comment="firefox is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:92737"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.4-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94935"/>
            <criterion comment="xulrunner is earlier than 0:10.0.4-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94820"/>
            <criterion comment="firefox is earlier than 0:10.0.4-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94789"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21331" version="68" class="patch">
      <metadata>
        <title>RHSA-2011:0413: glibc security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0413-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0413.html"/>
        <reference source="CVE" ref_id="CVE-2011-0536" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0536.html"/>
        <reference source="CVE" ref_id="CVE-2011-1071" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1071.html"/>
        <reference source="CVE" ref_id="CVE-2011-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1095.html"/>
        <reference source="CVE" ref_id="CVE-2011-1658" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1658.html"/>
        <reference source="CVE" ref_id="CVE-2011-1659" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1659.html"/>
        <description>Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:12.530-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:16.036-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:11.530-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-utils is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:97324"/>
          <criterion comment="glibc-devel is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:97788"/>
          <criterion comment="glibc is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:97696"/>
          <criterion comment="nscd is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:97832"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:97820"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:97778"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.7.el6_0.5" test_ref="oval:org.mitre.oval:tst:97828"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21328" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0410: raptor security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>raptor</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0410-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0410.html"/>
        <reference source="CESA" ref_id="CESA-2012:0410"/>
        <reference source="CVE" ref_id="CVE-2012-0037" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0037.html"/>
        <description>Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:44.582-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:02:15.833-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:11.318-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="raptor-devel is earlier than 0:1.4.18-5.el6_2.1" test_ref="oval:org.mitre.oval:tst:93119"/>
          <criterion comment="raptor is earlier than 0:1.4.18-5.el6_2.1" test_ref="oval:org.mitre.oval:tst:93146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21322" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0705: openoffice.org security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0705-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0705.html"/>
        <reference source="CESA" ref_id="CESA-2012:0705"/>
        <reference source="CVE" ref_id="CVE-2012-1149" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1149.html"/>
        <reference source="CVE" ref_id="CVE-2012-2334" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2334.html"/>
        <description>Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length of an Escher graphics record in a PowerPoint (.ppt) document, which triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:27.251-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:53.684-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:10.221-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93638"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93388"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93497"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93485"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93599"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93378"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92606"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93291"/>
            <criterion comment="openoffice.org-draw is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93552"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93544"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92627"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93163"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93448"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93054"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93488"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93171"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92820"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93153"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93545"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93504"/>
            <criterion comment="openoffice.org-calc is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92926"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93429"/>
            <criterion comment="openoffice.org-core is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93508"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93562"/>
            <criterion comment="openoffice.org-sdk is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92632"/>
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93216"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93457"/>
            <criterion comment="openoffice.org is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93501"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93495"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93177"/>
            <criterion comment="openoffice.org-impress is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93271"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93476"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92821"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93074"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93155"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93243"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93305"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93523"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93377"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93371"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93550"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93090"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93529"/>
            <criterion comment="openoffice.org-headless is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93449"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93313"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93106"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93129"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93466"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93489"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93553"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93479"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92806"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93360"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93430"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93568"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93532"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92927"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93468"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92611"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93463"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92907"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93603"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93509"/>
            <criterion comment="openoffice.org-base is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93563"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93569"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92666"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93122"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93218"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93440"/>
            <criterion comment="openoffice.org-ure is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92993"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92870"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93610"/>
            <criterion comment="openoffice.org-math is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93588"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93401"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93472"/>
            <criterion comment="openoffice.org-writer is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93409"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:92704"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.1.1-19.10.el5_8.3" test_ref="oval:org.mitre.oval:tst:93169"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93734"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93659"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93635"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93662"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93424"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93723"/>
            <criterion comment="autocorr-af is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92810"/>
            <criterion comment="openoffice.org-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93670"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93204"/>
            <criterion comment="openoffice.org-langpack-dz is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93702"/>
            <criterion comment="openoffice.org-sdk-doc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93768"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93697"/>
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93584"/>
            <criterion comment="broffice.org-brand is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93731"/>
            <criterion comment="autocorr-vi is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93464"/>
            <criterion comment="openoffice.org-langpack-uk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93745"/>
            <criterion comment="autocorr-ja is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93598"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93703"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93653"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93735"/>
            <criterion comment="openoffice.org-calc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93605"/>
            <criterion comment="openoffice.org-opensymbol-fonts is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93586"/>
            <criterion comment="autocorr-eu is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93361"/>
            <criterion comment="openoffice.org is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93543"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93730"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93737"/>
            <criterion comment="openoffice.org-presentation-minimizer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93636"/>
            <criterion comment="autocorr-sl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93556"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93684"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93754"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93631"/>
            <criterion comment="openoffice.org-draw is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93758"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93082"/>
            <criterion comment="openoffice.org-devel is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93580"/>
            <criterion comment="autocorr-ga is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93711"/>
            <criterion comment="openoffice.org-report-builder is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93683"/>
            <criterion comment="openoffice.org-calc-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93720"/>
            <criterion comment="autocorr-mn is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93676"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93587"/>
            <criterion comment="broffice.org-math is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93539"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93473"/>
            <criterion comment="autocorr-pl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93392"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93575"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93227"/>
            <criterion comment="openoffice.org-base-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93557"/>
            <criterion comment="broffice.org-writer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93203"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93715"/>
            <criterion comment="openoffice.org-brand is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93870"/>
            <criterion comment="broffice.org-impress is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93606"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93535"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93434"/>
            <criterion comment="autocorr-da is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92828"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93220"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93692"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93264"/>
            <criterion comment="openoffice.org-langpack-pa is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93708"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93195"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93628"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93691"/>
            <criterion comment="openoffice.org-writer is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93652"/>
            <criterion comment="broffice.org-calc is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93301"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92881"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93614"/>
            <criterion comment="autocorr-tr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93510"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93725"/>
            <criterion comment="autocorr-sv is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93182"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93490"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93719"/>
            <criterion comment="autocorr-fr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93477"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93637"/>
            <criterion comment="autocorr-es is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92929"/>
            <criterion comment="openoffice.org-langpack-ro is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93682"/>
            <criterion comment="openoffice.org-langpack-en is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93272"/>
            <criterion comment="autocorr-fi is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92874"/>
            <criterion comment="openoffice.org-impress is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93590"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93373"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93320"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93522"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93744"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93574"/>
            <criterion comment="openoffice.org-langpack-mai_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93498"/>
            <criterion comment="openoffice.org-wiki-publisher is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93281"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93690"/>
            <criterion comment="autocorr-de is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93622"/>
            <criterion comment="broffice.org-base is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93694"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93546"/>
            <criterion comment="openoffice.org-math is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93481"/>
            <criterion comment="autocorr-nl is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93395"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93433"/>
            <criterion comment="openoffice.org-draw-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93762"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93572"/>
            <criterion comment="autocorr-bg is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93531"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93831"/>
            <criterion comment="openoffice.org-bsh is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93192"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93760"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93462"/>
            <criterion comment="openoffice.org-langpack-sr is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93484"/>
            <criterion comment="openoffice.org-math-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93807"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93435"/>
            <criterion comment="autocorr-ru is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93616"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93826"/>
            <criterion comment="autocorr-en is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93600"/>
            <criterion comment="autocorr-sk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93511"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92924"/>
            <criterion comment="autocorr-lt is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93756"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93537"/>
            <criterion comment="autocorr-cs is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93693"/>
            <criterion comment="autocorr-pt is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93343"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93591"/>
            <criterion comment="openoffice.org-writer-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92771"/>
            <criterion comment="openoffice.org-sdk is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93582"/>
            <criterion comment="openoffice.org-rhino is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93087"/>
            <criterion comment="openoffice.org-presenter-screen is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93611"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93458"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93024"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93100"/>
            <criterion comment="openoffice.org-impress-core is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93592"/>
            <criterion comment="broffice.org-draw is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93470"/>
            <criterion comment="openoffice.org-pdfimport is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93482"/>
            <criterion comment="autocorr-fa is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93413"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92901"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93738"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93521"/>
            <criterion comment="autocorr-zh is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92831"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93649"/>
            <criterion comment="autocorr-ko is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93512"/>
            <criterion comment="openoffice.org-headless is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93542"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93673"/>
            <criterion comment="autocorr-it is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93515"/>
            <criterion comment="openoffice.org-ogltrans is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93761"/>
            <criterion comment="openoffice.org-base is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93642"/>
            <criterion comment="autocorr-hu is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93459"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93646"/>
            <criterion comment="openoffice.org-ure is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93374"/>
            <criterion comment="autocorr-lb is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:93375"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:3.2.1-19.6.el6_2.7" test_ref="oval:org.mitre.oval:tst:92909"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21318" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1116: perl-DBD-Pg security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>perl-DBD-Pg</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1116-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1116.html"/>
        <reference source="CESA" ref_id="CESA-2012:1116"/>
        <reference source="CVE" ref_id="CVE-2012-1151" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1151.html"/>
        <description>Multiple format string vulnerabilities in dbdimp.c in DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.19.0 for Perl allow remote PostgreSQL database servers to cause a denial of service (process crash) via format string specifiers in (1) a crafted database warning to the pg_warn function or (2) a crafted DBD statement to the dbd_st_prepare function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:34.595-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:53.484-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:09.811-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="perl-DBD-Pg is earlier than 0:1.49-4.el5_8" test_ref="oval:org.mitre.oval:tst:94094"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="perl-DBD-Pg is earlier than 0:2.15.1-4.el6_3" test_ref="oval:org.mitre.oval:tst:93969"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21317" version="237" class="patch">
      <metadata>
        <title>RHSA-2012:0105: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0105-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0105.html"/>
        <reference source="CESA" ref_id="CESA-2012:0105"/>
        <reference source="CVE" ref_id="CVE-2011-2262" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2262.html"/>
        <reference source="CVE" ref_id="CVE-2012-0075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0075.html"/>
        <reference source="CVE" ref_id="CVE-2012-0087" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0087.html"/>
        <reference source="CVE" ref_id="CVE-2012-0101" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0101.html"/>
        <reference source="CVE" ref_id="CVE-2012-0102" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0102.html"/>
        <reference source="CVE" ref_id="CVE-2012-0112" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0112.html"/>
        <reference source="CVE" ref_id="CVE-2012-0113" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0113.html"/>
        <reference source="CVE" ref_id="CVE-2012-0114" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0114.html"/>
        <reference source="CVE" ref_id="CVE-2012-0115" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0115.html"/>
        <reference source="CVE" ref_id="CVE-2012-0116" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0116.html"/>
        <reference source="CVE" ref_id="CVE-2012-0118" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0118.html"/>
        <reference source="CVE" ref_id="CVE-2012-0119" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0119.html"/>
        <reference source="CVE" ref_id="CVE-2012-0120" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0120.html"/>
        <reference source="CVE" ref_id="CVE-2012-0484" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0484.html"/>
        <reference source="CVE" ref_id="CVE-2012-0485" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0485.html"/>
        <reference source="CVE" ref_id="CVE-2012-0490" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0490.html"/>
        <reference source="CVE" ref_id="CVE-2012-0492" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0492.html"/>
        <reference source="CVE" ref_id="CVE-2012-0583" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0583.html"/>
        <description>Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:37.125-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:53.122-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:09.268-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-server is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:92995"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:92216"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:93016"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:92137"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:92916"/>
          <criterion comment="mysql-test is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:92978"/>
          <criterion comment="mysql is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:92887"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.61-1.el6_2.1" test_ref="oval:org.mitre.oval:tst:92789"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21314" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0093: php security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0093-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0093.html"/>
        <reference source="CESA" ref_id="CESA-2012:0093"/>
        <reference source="CVE" ref_id="CVE-2012-0830" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0830.html"/>
        <description>The php_register_variable_ex function in php_variables.c in PHP 5.3.9 allows remote attackers to execute arbitrary code via a request containing a large number of variables, related to improper handling of array variables.  NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4885.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:34.346-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:52.959-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:08.896-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-common is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:93036"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92893"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92388"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92989"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92965"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92902"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92659"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92803"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92195"/>
            <criterion comment="php is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92443"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92438"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92890"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92486"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92847"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92301"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92744"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92641"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:93042"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92923"/>
            <criterion comment="php-process is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92596"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92934"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92932"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92910"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92583"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92671"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-3.el6_2.6" test_ref="oval:org.mitre.oval:tst:92867"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-common is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92835"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92897"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:93017"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92732"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92886"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92690"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92422"/>
            <criterion comment="php is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92506"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92990"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92985"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92536"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92774"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92971"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92740"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92871"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92843"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92868"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92391"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-27.el5_7.5" test_ref="oval:org.mitre.oval:tst:92649"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21313" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0920: krb5-appl security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>krb5-appl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0920-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0920.html"/>
        <reference source="CVE" ref_id="CVE-2011-1526" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1526.html"/>
        <description>ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:24.634-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:52.893-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:08.786-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-appl-clients is earlier than 0:1.0.1-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:97751"/>
          <criterion comment="krb5-appl-servers is earlier than 0:1.0.1-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:97855"/>
          <criterion comment="krb5-appl is earlier than 0:1.0.1-2.el6_1.1" test_ref="oval:org.mitre.oval:tst:98222"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21312" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0475: tomcat6 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0475-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0475.html"/>
        <reference source="CESA" ref_id="CESA-2012:0475"/>
        <reference source="CVE" ref_id="CVE-2011-4858" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4858.html"/>
        <reference source="CVE" ref_id="CVE-2012-0022" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0022.html"/>
        <description>Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:20.584-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:52.786-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:08.611-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:93307"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:92872"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:93189"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:93369"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:93349"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:92915"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:93156"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:92395"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-36.el6_2" test_ref="oval:org.mitre.oval:tst:93352"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21311" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0869: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0869-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0869.html"/>
        <reference source="CVE" ref_id="CVE-2011-2110" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2110.html"/>
        <description>Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in June 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:55.301-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:52.719-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:08.502-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.181.26-1.el5" test_ref="oval:org.mitre.oval:tst:98024"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.181.26-1.el6" test_ref="oval:org.mitre.oval:tst:98242"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21310" version="263" class="patch">
      <metadata>
        <title>RHSA-2012:1351: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1351-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1351.html"/>
        <reference source="CESA" ref_id="CESA-2012:1351"/>
        <reference source="CVE" ref_id="CVE-2012-1956" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1956.html"/>
        <reference source="CVE" ref_id="CVE-2012-3982" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3982.html"/>
        <reference source="CVE" ref_id="CVE-2012-3986" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3986.html"/>
        <reference source="CVE" ref_id="CVE-2012-3988" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3988.html"/>
        <reference source="CVE" ref_id="CVE-2012-3990" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3990.html"/>
        <reference source="CVE" ref_id="CVE-2012-3991" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3991.html"/>
        <reference source="CVE" ref_id="CVE-2012-3992" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3992.html"/>
        <reference source="CVE" ref_id="CVE-2012-3993" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3993.html"/>
        <reference source="CVE" ref_id="CVE-2012-3994" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3994.html"/>
        <reference source="CVE" ref_id="CVE-2012-3995" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3995.html"/>
        <reference source="CVE" ref_id="CVE-2012-4179" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4179.html"/>
        <reference source="CVE" ref_id="CVE-2012-4180" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4180.html"/>
        <reference source="CVE" ref_id="CVE-2012-4181" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4181.html"/>
        <reference source="CVE" ref_id="CVE-2012-4182" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4182.html"/>
        <reference source="CVE" ref_id="CVE-2012-4183" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4183.html"/>
        <reference source="CVE" ref_id="CVE-2012-4184" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4184.html"/>
        <reference source="CVE" ref_id="CVE-2012-4185" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4185.html"/>
        <reference source="CVE" ref_id="CVE-2012-4186" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4186.html"/>
        <reference source="CVE" ref_id="CVE-2012-4187" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4187.html"/>
        <reference source="CVE" ref_id="CVE-2012-4188" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4188.html"/>
        <description>Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:54.628-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:52.081-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:07.981-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el5_8" test_ref="oval:org.mitre.oval:tst:94671"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94846"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el6_3" test_ref="oval:org.mitre.oval:tst:94372"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.8-1.el6.centos" test_ref="oval:org.mitre.oval:tst:95080"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21309" version="120" class="patch">
      <metadata>
        <title>RHSA-2012:0729: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0729-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0729.html"/>
        <reference source="CESA" ref_id="CESA-2012:0729"/>
        <reference source="CVE" ref_id="CVE-2012-1711" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1711.html"/>
        <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
        <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
        <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
        <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
        <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
        <reference source="CVE" ref_id="CVE-2012-1723" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1723.html"/>
        <reference source="CVE" ref_id="CVE-2012-1724" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1724.html"/>
        <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, and 5 update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:22.130-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:51.666-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:07.643-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:93736"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:93294"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:93657"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:93704"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.48.1.11.3.el6_2" test_ref="oval:org.mitre.oval:tst:93834"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21307" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1363: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1363-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1363.html"/>
        <reference source="CESA" ref_id="CESA-2012:1363"/>
        <reference source="CVE" ref_id="CVE-2012-5166" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5166.html"/>
        <description>ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:08.192-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:51.470-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:07.428-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94747"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94716"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94743"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94721"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94030"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94663"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94424"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.5" test_ref="oval:org.mitre.oval:tst:94750"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:94460"/>
            <criterion comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:94678"/>
            <criterion comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:94569"/>
            <criterion comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:94202"/>
            <criterion comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:94555"/>
            <criterion comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.5" test_ref="oval:org.mitre.oval:tst:93984"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21301" version="44" class="patch">
      <metadata>
        <title>RHSA-2011:0862: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0862-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0862.html"/>
        <reference source="CVE" ref_id="CVE-2011-1752" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1752.html"/>
        <reference source="CVE" ref_id="CVE-2011-1783" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1783.html"/>
        <reference source="CVE" ref_id="CVE-2011-1921" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1921.html"/>
        <reference source="CESA-2011:0862" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-June/017614.html" ref_id="CESA-2011:0862-CentOS 5"/>
        <description>The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is disabled, does not properly enforce permissions for files that had been publicly readable in the past, which allows remote attackers to obtain sensitive information via a replay REPORT operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:14.691-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:51.150-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:07.124-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21301 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:29.244-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:58.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137908"/>
            <criterion comment="subversion is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137788"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:136956"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137746"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137709"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-7.el5_6.4" test_ref="oval:org.mitre.oval:tst:137267"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:97942"/>
            <criterion comment="subversion is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:98168"/>
            <criterion comment="subversion-debuginfo is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:137907"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:97266"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:97627"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:97915"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:97818"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:98187"/>
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:98000"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_1.4" test_ref="oval:org.mitre.oval:tst:98134"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21298" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1359: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1359-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1359.html"/>
        <reference source="CESA" ref_id="CESA-2012:1359"/>
        <reference source="CVE" ref_id="CVE-2012-4423" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4423.html"/>
        <description>The virNetServerProgramDispatchCall function in libvirt before 0.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and segmentation fault) via an RPC call with (1) an event as the RPC number or (2) an RPC number whose value is in a "gap" in the RPC dispatch table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:30.410-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:50.955-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:06.869-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.el6_3.5" test_ref="oval:org.mitre.oval:tst:94575"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.el6_3.5" test_ref="oval:org.mitre.oval:tst:94287"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.el6_3.5" test_ref="oval:org.mitre.oval:tst:94149"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.9.10-21.el6_3.5" test_ref="oval:org.mitre.oval:tst:94439"/>
          <criterion comment="libvirt is earlier than 0:0.9.10-21.el6_3.5" test_ref="oval:org.mitre.oval:tst:94592"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21296" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0058: glibc security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0058-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0058.html"/>
        <reference source="CESA" ref_id="CESA-2012:0058"/>
        <reference source="CVE" ref_id="CVE-2009-5029" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-5029.html"/>
        <reference source="CVE" ref_id="CVE-2011-4609" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4609.html"/>
        <description>The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service (CPU consumption) via a large number of RPC connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:06.281-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:50.654-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:06.578-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-devel is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:91834"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:92561"/>
          <criterion comment="glibc is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:92784"/>
          <criterion comment="nscd is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:92603"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:92792"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:92599"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.47.el6_2.5" test_ref="oval:org.mitre.oval:tst:92069"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21289" version="107" class="patch">
      <metadata>
        <title>RHSA-2012:1173: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1173-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1173.html"/>
        <reference source="CVE" ref_id="CVE-2012-1535" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1535.html"/>
        <reference source="CVE" ref_id="CVE-2012-4163" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4163.html"/>
        <reference source="CVE" ref_id="CVE-2012-4164" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4164.html"/>
        <reference source="CVE" ref_id="CVE-2012-4165" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4165.html"/>
        <reference source="CVE" ref_id="CVE-2012-4166" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4166.html"/>
        <reference source="CVE" ref_id="CVE-2012-4167" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4167.html"/>
        <reference source="CVE" ref_id="CVE-2012-4168" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4168.html"/>
        <reference source="CVE" ref_id="CVE-2012-5054" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5054.html"/>
        <description>Integer overflow in the copyRawDataTo method in the Matrix3D class in Adobe Flash Player before 11.4.402.265 allows remote attackers to execute arbitrary code via malformed arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:33.821-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:50.106-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:05.816-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="flash-plugin is earlier than 0:11.2.202.238-1.el6" test_ref="oval:org.mitre.oval:tst:94359"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21284" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1221: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1221-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1221.html"/>
        <reference source="CESA" ref_id="CESA-2012:1221"/>
        <reference source="CVE" ref_id="CVE-2012-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0547.html"/>
        <reference source="CVE" ref_id="CVE-2012-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1682.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans, a different vulnerability than CVE-2012-3136.  NOTE: Oracle has not commented on claims from a downstream vendor that this issue is related to "XMLDecoder security issue via ClassFinder."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:32.478-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:49.618-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:05.075-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:94076"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:94285"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:94319"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:94415"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.49.1.11.4.el6_3" test_ref="oval:org.mitre.oval:tst:94389"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21283" version="117" class="patch">
      <metadata>
        <title>RHSA-2013:1823: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1823-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1823.html"/>
        <reference source="CESA" ref_id="CESA-2013:1823"/>
        <reference source="CVE" ref_id="CVE-2013-0772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5609" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5609.html"/>
        <reference source="CVE" ref_id="CVE-2013-5612" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5612.html"/>
        <reference source="CVE" ref_id="CVE-2013-5613" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5613.html"/>
        <reference source="CVE" ref_id="CVE-2013-5614" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5614.html"/>
        <reference source="CVE" ref_id="CVE-2013-5616" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5616.html"/>
        <reference source="CVE" ref_id="CVE-2013-5618" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5618.html"/>
        <reference source="CVE" ref_id="CVE-2013-6671" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6671.html"/>
        <description>The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:17.748-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:24.774-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:38.090-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21283 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:40.695-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:34.721-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-2.el5_10" test_ref="oval:org.mitre.oval:tst:91943"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:24.2.0-2.el5.centos" test_ref="oval:org.mitre.oval:tst:91862"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:91932"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:24.2.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92056"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21282" version="185" class="patch">
      <metadata>
        <title>RHSA-2012:1089: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1089-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1089.html"/>
        <reference source="CESA" ref_id="CESA-2012:1089"/>
        <reference source="CVE" ref_id="CVE-2012-1948" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1948.html"/>
        <reference source="CVE" ref_id="CVE-2012-1951" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1951.html"/>
        <reference source="CVE" ref_id="CVE-2012-1952" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1952.html"/>
        <reference source="CVE" ref_id="CVE-2012-1953" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1953.html"/>
        <reference source="CVE" ref_id="CVE-2012-1954" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1954.html"/>
        <reference source="CVE" ref_id="CVE-2012-1955" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1955.html"/>
        <reference source="CVE" ref_id="CVE-2012-1957" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1957.html"/>
        <reference source="CVE" ref_id="CVE-2012-1958" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1958.html"/>
        <reference source="CVE" ref_id="CVE-2012-1959" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1959.html"/>
        <reference source="CVE" ref_id="CVE-2012-1961" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1961.html"/>
        <reference source="CVE" ref_id="CVE-2012-1962" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1962.html"/>
        <reference source="CVE" ref_id="CVE-2012-1963" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1963.html"/>
        <reference source="CVE" ref_id="CVE-2012-1964" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1964.html"/>
        <reference source="CVE" ref_id="CVE-2012-1967" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1967.html"/>
        <description>Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 do not properly implement the JavaScript sandbox utility, which allows remote attackers to execute arbitrary JavaScript code with improper privileges via a javascript: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:00.080-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:44.354-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:04.645-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el5_8" test_ref="oval:org.mitre.oval:tst:93890"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94942"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:93836"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94863"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21280" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0716: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0716-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0716.html"/>
        <reference source="CESA" ref_id="CESA-2012:0716"/>
        <reference source="CVE" ref_id="CVE-2012-1033" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1033.html"/>
        <reference source="CVE" ref_id="CVE-2012-1667" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1667.html"/>
        <description>ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:00.188-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:44.166-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:04.492-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93872"/>
            <criterion comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93808"/>
            <criterion comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93133"/>
            <criterion comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93803"/>
            <criterion comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93660"/>
            <criterion comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93455"/>
            <criterion comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93618"/>
            <criterion comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.1" test_ref="oval:org.mitre.oval:tst:93794"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="bind is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93755"/>
            <criterion comment="bind-chroot is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93619"/>
            <criterion comment="bind-sdb is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93828"/>
            <criterion comment="bind-libs is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93687"/>
            <criterion comment="bind-utils is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93726"/>
            <criterion comment="bind-devel is earlier than 32:9.7.3-8.P3.el6_2.3" test_ref="oval:org.mitre.oval:tst:93341"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21279" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0426: openssl security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0426-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0426.html"/>
        <reference source="CESA" ref_id="CESA-2012:0426"/>
        <reference source="CVE" ref_id="CVE-2012-0884" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0884.html"/>
        <reference source="CVE" ref_id="CVE-2012-1165" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1165.html"/>
        <description>The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:45.614-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:44.011-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:04.343-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:92404"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:93315"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-22.el5_8.1" test_ref="oval:org.mitre.oval:tst:93324"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:93210"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:93212"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:92765"/>
            <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.3" test_ref="oval:org.mitre.oval:tst:93257"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21278" version="120" class="patch">
      <metadata>
        <title>RHSA-2012:1259: quagga security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>quagga</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1259-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1259.html"/>
        <reference source="CESA" ref_id="CESA-2012:1259"/>
        <reference source="CVE" ref_id="CVE-2011-3323" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3323.html"/>
        <reference source="CVE" ref_id="CVE-2011-3324" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3324.html"/>
        <reference source="CVE" ref_id="CVE-2011-3325" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3325.html"/>
        <reference source="CVE" ref_id="CVE-2011-3326" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3326.html"/>
        <reference source="CVE" ref_id="CVE-2011-3327" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3327.html"/>
        <reference source="CVE" ref_id="CVE-2012-0249" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0249.html"/>
        <reference source="CVE" ref_id="CVE-2012-0250" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0250.html"/>
        <reference source="CVE" ref_id="CVE-2012-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0255.html"/>
        <reference source="CVE" ref_id="CVE-2012-1820" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1820.html"/>
        <description>The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:42.741-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:43.732-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:03.978-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="quagga-devel is earlier than 0:0.99.15-7.el6_3.2" test_ref="oval:org.mitre.oval:tst:94151"/>
          <criterion comment="quagga-contrib is earlier than 0:0.99.15-7.el6_3.2" test_ref="oval:org.mitre.oval:tst:94402"/>
          <criterion comment="quagga is earlier than 0:0.99.15-7.el6_3.2" test_ref="oval:org.mitre.oval:tst:94417"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21277" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1457: libgcrypt security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libgcrypt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1457-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1457.html"/>
        <reference source="CESA" ref_id="CESA-2013:1457"/>
        <reference source="CVE" ref_id="CVE-2013-4242" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4242.html"/>
        <description>GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:27.148-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:24.401-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:37.759-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:91628"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.5-11.el6_4" test_ref="oval:org.mitre.oval:tst:91830"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libgcrypt-devel is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:91601"/>
            <criterion comment="libgcrypt is earlier than 0:1.4.4-7.el5_10" test_ref="oval:org.mitre.oval:tst:91398"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21275" version="5" class="patch">
      <metadata>
        <title>RHSA-2011:0374: thunderbird security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0374-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0374.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

This erratum blacklists a small number of HTTPS certificates. (BZ#689430)

This update also fixes the following bug:

* The RHSA-2011:0312 and RHSA-2011:0311 updates introduced a regression,
preventing some Java content and plug-ins written in Java from loading.
With this update, the Java content and plug-ins work as expected.
(BZ#683076)

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:26.369-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:43.680-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:03.916-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21275 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.934-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:34.611-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.24-15.el5_6" test_ref="oval:org.mitre.oval:tst:97616"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="thunderbird is earlier than 0:3.1.9-3.el6_0" test_ref="oval:org.mitre.oval:tst:97486"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21273" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0290: java-1.6.0-ibm security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0290-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0290.html"/>
        <reference source="CVE" ref_id="CVE-2010-4476" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4476.html"/>
        <description>The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:52.350-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:43.479-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:03.647-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97234"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97396"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97362"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97439"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97383"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97504"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:97068"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el5" test_ref="oval:org.mitre.oval:tst:96560"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97259"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:96596"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97479"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97343"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97548"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97462"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.5.el6" test_ref="oval:org.mitre.oval:tst:97444"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21268" version="302" class="patch">
      <metadata>
        <title>RHSA-2012:1211: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1211-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1211.html"/>
        <reference source="CESA" ref_id="CESA-2012:1211"/>
        <reference source="CVE" ref_id="CVE-2012-1970" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1970.html"/>
        <reference source="CVE" ref_id="CVE-2012-1972" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1972.html"/>
        <reference source="CVE" ref_id="CVE-2012-1973" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1973.html"/>
        <reference source="CVE" ref_id="CVE-2012-1974" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1974.html"/>
        <reference source="CVE" ref_id="CVE-2012-1975" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1975.html"/>
        <reference source="CVE" ref_id="CVE-2012-1976" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1976.html"/>
        <reference source="CVE" ref_id="CVE-2012-3956" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3956.html"/>
        <reference source="CVE" ref_id="CVE-2012-3957" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3957.html"/>
        <reference source="CVE" ref_id="CVE-2012-3958" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3958.html"/>
        <reference source="CVE" ref_id="CVE-2012-3959" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3959.html"/>
        <reference source="CVE" ref_id="CVE-2012-3960" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3960.html"/>
        <reference source="CVE" ref_id="CVE-2012-3961" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3961.html"/>
        <reference source="CVE" ref_id="CVE-2012-3962" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3962.html"/>
        <reference source="CVE" ref_id="CVE-2012-3963" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3963.html"/>
        <reference source="CVE" ref_id="CVE-2012-3964" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3964.html"/>
        <reference source="CVE" ref_id="CVE-2012-3966" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3966.html"/>
        <reference source="CVE" ref_id="CVE-2012-3967" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3967.html"/>
        <reference source="CVE" ref_id="CVE-2012-3968" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3968.html"/>
        <reference source="CVE" ref_id="CVE-2012-3969" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3969.html"/>
        <reference source="CVE" ref_id="CVE-2012-3970" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3970.html"/>
        <reference source="CVE" ref_id="CVE-2012-3972" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3972.html"/>
        <reference source="CVE" ref_id="CVE-2012-3978" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3978.html"/>
        <reference source="CVE" ref_id="CVE-2012-3980" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3980.html"/>
        <description>The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:41.791-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:42.326-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:02.376-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el5_8" test_ref="oval:org.mitre.oval:tst:94373"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94599"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el6_3" test_ref="oval:org.mitre.oval:tst:94386"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:95015"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21264" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0468: libtiff security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtiff</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0468-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0468.html"/>
        <reference source="CESA" ref_id="CESA-2012:0468"/>
        <reference source="CVE" ref_id="CVE-2012-1173" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1173.html"/>
        <description>Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9.4 allow remote attackers to execute arbitrary code via a crafted tile size in a TIFF file, which is not properly handled by the (1) gtTileSeparate or (2) gtStripSeparate function, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:35.188-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:42.074-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:02.118-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:93059"/>
            <criterion comment="libtiff-devel is earlier than 0:3.8.2-14.el5_8" test_ref="oval:org.mitre.oval:tst:93328"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libtiff is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:93286"/>
            <criterion comment="libtiff-static is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:93196"/>
            <criterion comment="libtiff-devel is earlier than 0:3.9.4-5.el6_2" test_ref="oval:org.mitre.oval:tst:92360"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21263" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:1866: ca-certificates security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ca-certificate</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1866-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1866.html"/>
        <reference source="CESA" ref_id="CESA-2013:1866"/>
        <description>This package contains the set of CA certificates chosen by the Mozilla
Foundation for use with the Internet Public Key Infrastructure (PKI).

It was found that a subordinate Certificate Authority (CA) mis-issued an
intermediate certificate, which could be used to conduct man-in-the-middle
attacks. This update renders that particular intermediate certificate as
untrusted. (BZ#1038894)

All users should upgrade to this updated package. After installing the
update, all applications using the ca-certificates package must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:40.021-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:24.341-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:37.675-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21263 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.416-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:33.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="ca-certificates is earlier than 0:2013.1.95-65.1.el6_5" test_ref="oval:org.mitre.oval:tst:92113"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21262" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:1778: gimp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>gimp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1778-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1778.html"/>
        <reference source="CESA" ref_id="CESA-2013:1778"/>
        <reference source="CVE" ref_id="CVE-2012-5576" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5576.html"/>
        <reference source="CVE" ref_id="CVE-2013-1913" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1913.html"/>
        <reference source="CVE" ref_id="CVE-2013-1978" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1978.html"/>
        <description>Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:13.507-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:24.135-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:37.474-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gimp-libs is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:91590"/>
            <criterion comment="gimp-devel is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:91702"/>
            <criterion comment="gimp is earlier than 2:2.2.13-3.el5_10" test_ref="oval:org.mitre.oval:tst:91761"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gimp-libs is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:91665"/>
            <criterion comment="gimp-devel-tools is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:91759"/>
            <criterion comment="gimp-devel is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:91897"/>
            <criterion comment="gimp is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:91877"/>
            <criterion comment="gimp-help-browser is earlier than 2:2.6.9-6.el6_5" test_ref="oval:org.mitre.oval:tst:91673"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21261" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1500: gc security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>gc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1500-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1500.html"/>
        <reference source="CESA" ref_id="CESA-2013:1500"/>
        <reference source="CVE" ref_id="CVE-2012-2673" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2673.html"/>
        <description>Multiple integer overflows in the (1) GC_generic_malloc and (2) calloc funtions in malloc.c, and the (3) GC_generic_malloc_ignore_off_page function in mallocx.c in Boehm-Demers-Weiser GC (libgc) before 7.2 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which causes less memory to be allocated than expected.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:49.712-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:24.021-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:37.352-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gc-devel is earlier than 0:7.1-12.el6_4" test_ref="oval:org.mitre.oval:tst:91620"/>
          <criterion comment="gc is earlier than 0:7.1-12.el6_4" test_ref="oval:org.mitre.oval:tst:91689"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21259" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0013: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0013-02" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0013.html"/>
        <reference source="CVE" ref_id="CVE-2010-4538" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4538.html"/>
        <description>Buffer overflow in the sect_enttec_dmx_da function in epan/dissectors/packet-enttec.c in Wireshark 1.4.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ENTTEC DMX packet with Run Length Encoding (RLE) compression.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:39:21.974-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:41.864-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:01.908-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="wireshark is earlier than 0:1.0.15-1.el5_5.3" test_ref="oval:org.mitre.oval:tst:96536"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.15-1.el5_5.3" test_ref="oval:org.mitre.oval:tst:96857"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="wireshark is earlier than 0:1.2.13-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96885"/>
            <criterion comment="wireshark-devel is earlier than 0:1.2.13-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96415"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.2.13-1.el6_0.2" test_ref="oval:org.mitre.oval:tst:96853"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21258" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1366: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1366-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1366.html"/>
        <reference source="CESA" ref_id="CESA-2012:1366"/>
        <reference source="CVE" ref_id="CVE-2012-3412" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3412.html"/>
        <description>The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:41.326-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:41.751-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:01.762-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94589"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94387"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94625"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94615"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94602"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94607"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94782"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94225"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94092"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:93858"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94568"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.11.1.el6" test_ref="oval:org.mitre.oval:tst:94645"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21256" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:1272: libvirt security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1272-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1272.html"/>
        <reference source="CESA" ref_id="CESA-2013:1272"/>
        <reference source="CVE" ref_id="CVE-2013-4296" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4296.html"/>
        <reference source="CVE" ref_id="CVE-2013-4311" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4311.html"/>
        <description>libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:27.349-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:23.878-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:37.216-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-18.el6_4.14" test_ref="oval:org.mitre.oval:tst:91652"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-18.el6_4.14" test_ref="oval:org.mitre.oval:tst:91216"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-18.el6_4.14" test_ref="oval:org.mitre.oval:tst:91513"/>
          <criterion comment="libvirt is earlier than 0:0.10.2-18.el6_4.14" test_ref="oval:org.mitre.oval:tst:91666"/>
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-18.el6_4.14" test_ref="oval:org.mitre.oval:tst:91607"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21252" version="28" class="patch">
      <metadata>
        <title>RHSA-2012:1098: glibc security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>glibc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1098-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1098.html"/>
        <reference source="CESA" ref_id="CESA-2012:1098"/>
        <reference source="CVE" ref_id="CVE-2012-3404" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3404.html"/>
        <reference source="CVE" ref_id="CVE-2012-3405" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3405.html"/>
        <reference source="CVE" ref_id="CVE-2012-3406" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3406.html"/>
        <description>The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (crash) or possibly execute arbitrary code via a crafted format string using positional parameters and a large number of format specifiers, a different vulnerability than CVE-2012-3404 and CVE-2012-3405.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:10.333-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:40.882-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:01.001-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="glibc-devel is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:93925"/>
          <criterion comment="glibc-utils is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:93507"/>
          <criterion comment="glibc is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:93866"/>
          <criterion comment="nscd is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:93789"/>
          <criterion comment="glibc-static is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:93952"/>
          <criterion comment="glibc-common is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:93939"/>
          <criterion comment="glibc-headers is earlier than 0:2.12-1.80.el6_3.3" test_ref="oval:org.mitre.oval:tst:93964"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21249" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1091: nss, nspr, and nss-util security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1091-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1091.html"/>
        <reference source="CESA" ref_id="CESA-2012:1091"/>
        <reference source="CVE" ref_id="CVE-2012-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0441.html"/>
        <description>The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10, allows remote attackers to cause a denial of service (application crash) via a zero-length item, as demonstrated by (1) a zero-length basic constraint or (2) a zero-length field in an OCSP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:18.955-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:40.578-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:00.537-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nss-util is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:93985"/>
          <criterion comment="nss-util-devel is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:93397"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:93400"/>
          <criterion comment="nss-tools is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:93944"/>
          <criterion comment="nss-sysinit is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:94128"/>
          <criterion comment="nss is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:93214"/>
          <criterion comment="nss-devel is earlier than 0:3.13.5-1.el6_3" test_ref="oval:org.mitre.oval:tst:94050"/>
          <criterion comment="nspr is earlier than 0:4.9.1-2.el6_3" test_ref="oval:org.mitre.oval:tst:94018"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.1-2.el6_3" test_ref="oval:org.mitre.oval:tst:94014"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21247" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1764: ruby security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1764-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1764.html"/>
        <reference source="CESA" ref_id="CESA-2013:1764"/>
        <reference source="CVE" ref_id="CVE-2013-4164" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4164.html"/>
        <description>Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allows context-dependent attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a string that is converted to a floating point value, as demonstrated using (1) the to_f method or (2) JSON.parse.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:42.505-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:23.748-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:37.082-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:91832"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:91168"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:91876"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:91653"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:91592"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:91371"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:91749"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:91429"/>
          <criterion comment="ruby is earlier than 0:1.8.7.352-13.el6" test_ref="oval:org.mitre.oval:tst:91509"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21246" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1274: hplip security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>hplip</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1274-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1274.html"/>
        <reference source="CESA" ref_id="CESA-2013:1274"/>
        <reference source="CVE" ref_id="CVE-2013-4325" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4325.html"/>
        <description>The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:45.950-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:23.611-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:36.961-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="hplip-common is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:91625"/>
          <criterion comment="hplip-libs is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:91531"/>
          <criterion comment="libsane-hpaio is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:91588"/>
          <criterion comment="hplip is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:91548"/>
          <criterion comment="hplip-gui is earlier than 0:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:91063"/>
          <criterion comment="hpijs is earlier than 1:3.12.4-4.el6_4.1" test_ref="oval:org.mitre.oval:tst:90714"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21243" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0831: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0831-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0831.html"/>
        <reference source="CESA" ref_id="CESA-2013:0831"/>
        <reference source="CVE" ref_id="CVE-2013-1962" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1962.html"/>
        <description>The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of requests "to list all volumes for the particular pool."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:36.293-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:23.495-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:36.839-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-18.el6_4.5" test_ref="oval:org.mitre.oval:tst:91206"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-18.el6_4.5" test_ref="oval:org.mitre.oval:tst:90509"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-18.el6_4.5" test_ref="oval:org.mitre.oval:tst:90308"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-18.el6_4.5" test_ref="oval:org.mitre.oval:tst:90865"/>
          <criterion comment="libvirt is earlier than 0:0.10.2-18.el6_4.5" test_ref="oval:org.mitre.oval:tst:91231"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21241" version="229" class="patch">
      <metadata>
        <title>RHSA-2013:0855: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0855-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0855.html"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1491.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2394" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2394.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2432.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2013-2394 and CVE-2013-1491.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:44.309-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:22.801-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:36.268-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21241 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:30.082-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:57.296-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137691"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137614"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137026"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137722"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:136824"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137726"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137814"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137453"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91156"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91293"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91092"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90316"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91259"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90805"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91237"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21240" version="551" class="patch">
      <metadata>
        <title>RHSA-2013:1508: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1508-04" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1508.html"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4041" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4041.html"/>
        <reference source="CVE" ref_id="CVE-2013-5372" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5372.html"/>
        <reference source="CVE" ref_id="CVE-2013-5375" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5375.html"/>
        <reference source="CVE" ref_id="CVE-2013-5457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5457.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5776.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5787.html"/>
        <reference source="CVE" ref_id="CVE-2013-5789" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5789.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5801.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5812" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5812.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5818" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5818.html"/>
        <reference source="CVE" ref_id="CVE-2013-5819" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5819.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5824" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5824.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5831" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5831.html"/>
        <reference source="CVE" ref_id="CVE-2013-5832" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5832.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5843" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5843.html"/>
        <reference source="CVE" ref_id="CVE-2013-5848" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5848.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <reference source="CVE" ref_id="CVE-2013-5851" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5851.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:09.322-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:21.387-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:35.637-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21240 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:27.608-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:53.828-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137595"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137823"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137810"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137816"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137378"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137597"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137559"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:136830"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91425"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91900"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91281"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91817"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91073"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91412"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91719"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21239" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1081: sudo security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>sudo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1081-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1081.html"/>
        <reference source="CESA" ref_id="CESA-2012:1081"/>
        <reference source="CVE" ref_id="CVE-2012-2337" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2337.html"/>
        <description>sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local users to bypass intended command restrictions in opportunistic circumstances by executing a command on a host that has an IPv4 address.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:23.455-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:40.148-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:01:00.148-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="sudo is earlier than 0:1.7.2p1-14.el5_8" test_ref="oval:org.mitre.oval:tst:93943"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="sudo is earlier than 0:1.7.4p5-12.el6_3" test_ref="oval:org.mitre.oval:tst:93880"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21235" version="157" class="patch">
      <metadata>
        <title>RHSA-2013:1051: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1051-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1051.html"/>
        <reference source="CESA" ref_id="CESA-2013:1051"/>
        <reference source="CVE" ref_id="CVE-2012-6548" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6548.html"/>
        <reference source="CVE" ref_id="CVE-2013-0914" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0914.html"/>
        <reference source="CVE" ref_id="CVE-2013-1848" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1848.html"/>
        <reference source="CVE" ref_id="CVE-2013-2128" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2128.html"/>
        <reference source="CVE" ref_id="CVE-2013-2634" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2634.html"/>
        <reference source="CVE" ref_id="CVE-2013-2635" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2635.html"/>
        <reference source="CVE" ref_id="CVE-2013-2852" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2852.html"/>
        <reference source="CVE" ref_id="CVE-2013-3222" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3222.html"/>
        <reference source="CVE" ref_id="CVE-2013-3224" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3224.html"/>
        <reference source="CVE" ref_id="CVE-2013-3225" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3225.html"/>
        <reference source="CVE" ref_id="CVE-2013-3301" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3301.html"/>
        <description>The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:53.612-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:20.885-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:35.308-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91257"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91373"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91571"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91555"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91507"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:90968"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91374"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91467"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91154"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91551"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91222"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.14.1.el6" test_ref="oval:org.mitre.oval:tst:91470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21228" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1114: bind security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1114-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1114.html"/>
        <reference source="CESA" ref_id="CESA-2013:1114"/>
        <reference source="CVE" ref_id="CVE-2013-4854" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4854.html"/>
        <description>The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:15.686-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:20.641-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:35.050-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:91394"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:91367"/>
          <criterion comment="bind is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:91524"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:91432"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:91123"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.17.rc1.el6_4.5" test_ref="oval:org.mitre.oval:tst:91602"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21226" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1452: vino security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>vino</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1452-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1452.html"/>
        <reference source="CESA" ref_id="CESA-2013:1452"/>
        <reference source="CVE" ref_id="CVE-2013-5745" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5745.html"/>
        <description>The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service (infinite loop, CPU and disk consumption) via multiple crafted requests during authentication.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:34.240-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:20.531-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:34.929-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criterion comment="vino is earlier than 0:2.28.1-9.el6_4" test_ref="oval:org.mitre.oval:tst:91451"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="vino is earlier than 0:2.13.5-10.el5_10" test_ref="oval:org.mitre.oval:tst:91446"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21220" version="159" class="patch">
      <metadata>
        <title>RHSA-2012:0516: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0516-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0516.html"/>
        <reference source="CESA" ref_id="CESA-2012:0516"/>
        <reference source="CVE" ref_id="CVE-2011-3062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3062.html"/>
        <reference source="CVE" ref_id="CVE-2012-0467" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0467.html"/>
        <reference source="CVE" ref_id="CVE-2012-0468" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0468.html"/>
        <reference source="CVE" ref_id="CVE-2012-0469" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0469.html"/>
        <reference source="CVE" ref_id="CVE-2012-0470" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0470.html"/>
        <reference source="CVE" ref_id="CVE-2012-0471" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0471.html"/>
        <reference source="CVE" ref_id="CVE-2012-0472" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0472.html"/>
        <reference source="CVE" ref_id="CVE-2012-0473" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0473.html"/>
        <reference source="CVE" ref_id="CVE-2012-0474" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0474.html"/>
        <reference source="CVE" ref_id="CVE-2012-0477" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0477.html"/>
        <reference source="CVE" ref_id="CVE-2012-0478" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0478.html"/>
        <reference source="CVE" ref_id="CVE-2012-0479" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0479.html"/>
        <description>Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to spoof the address bar via an https URL for invalid (1) RSS or (2) Atom XML content.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:37.162-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:38.802-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:58.410-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el5_8" test_ref="oval:org.mitre.oval:tst:93012"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94095"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el6_2" test_ref="oval:org.mitre.oval:tst:93057"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.4-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94905"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21219" version="495" class="patch">
      <metadata>
        <title>RHSA-2013:1059: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1059-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1059.html"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2437.html"/>
        <reference source="CVE" ref_id="CVE-2013-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2442.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2451.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2464.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2466" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2466.html"/>
        <reference source="CVE" ref_id="CVE-2013-2468" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2468.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <reference source="CVE" ref_id="CVE-2013-3009" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3009.html"/>
        <reference source="CVE" ref_id="CVE-2013-3011" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3011.html"/>
        <reference source="CVE" ref_id="CVE-2013-3012" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3012.html"/>
        <reference source="CVE" ref_id="CVE-2013-3743" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3743.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:36.803-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:18.917-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:34.183-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21219 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:19.257-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:51.124-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137369"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137731"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137370"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137083"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137748"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137661"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137754"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.14.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137651"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91292"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91414"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91096"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91508"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91175"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91161"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.14.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21216" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0883: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0883-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0883.html"/>
        <reference source="CESA" ref_id="CESA-2013:0883"/>
        <reference source="CVE" ref_id="CVE-2013-2116" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2116.html"/>
        <description>The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length.  NOTE: this might be due to an incorrect fix for CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:05.577-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:18.785-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:34.054-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:90322"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:91153"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:90343"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:91149"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:91155"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:91306"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.2" test_ref="oval:org.mitre.oval:tst:91116"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21214" version="148" class="patch">
      <metadata>
        <title>RHSA-2011:0310: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0310-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0310.html"/>
        <reference source="CVE" ref_id="CVE-2010-1585" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-1585.html"/>
        <reference source="CVE" ref_id="CVE-2011-0051" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0051.html"/>
        <reference source="CVE" ref_id="CVE-2011-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0053.html"/>
        <reference source="CVE" ref_id="CVE-2011-0054" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0054.html"/>
        <reference source="CVE" ref_id="CVE-2011-0055" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0055.html"/>
        <reference source="CVE" ref_id="CVE-2011-0056" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0056.html"/>
        <reference source="CVE" ref_id="CVE-2011-0057" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0057.html"/>
        <reference source="CVE" ref_id="CVE-2011-0058" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0058.html"/>
        <reference source="CVE" ref_id="CVE-2011-0059" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0059.html"/>
        <reference source="CVE" ref_id="CVE-2011-0061" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0061.html"/>
        <reference source="CVE" ref_id="CVE-2011-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0062.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:10.167-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:38.350-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:57.940-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21214 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:18.319-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:49.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.14-4.el5_6" test_ref="oval:org.mitre.oval:tst:137752"/>
            <criterion comment="firefox is earlier than 0:3.6.14-4.el5_6" test_ref="oval:org.mitre.oval:tst:137866"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.14-4.el5_6" test_ref="oval:org.mitre.oval:tst:137487"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="firefox is earlier than 0:3.6.14-4.el6_0" test_ref="oval:org.mitre.oval:tst:97514"/>
            <criterion comment="firefox-debuginfo is earlier than 0:3.6.14-4.el6_0" test_ref="oval:org.mitre.oval:tst:137768"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.14-3.el6_0" test_ref="oval:org.mitre.oval:tst:97205"/>
            <criterion comment="xulrunner-debuginfo is earlier than 0:1.9.2.14-3.el6_0" test_ref="oval:org.mitre.oval:tst:137542"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.14-3.el6_0" test_ref="oval:org.mitre.oval:tst:97443"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21213" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0897: mesa security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mesa</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0897-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0897.html"/>
        <reference source="CESA" ref_id="CESA-2013:0897"/>
        <reference source="CVE" ref_id="CVE-2013-1872" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1872.html"/>
        <reference source="CVE" ref_id="CVE-2013-1993" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1993.html"/>
        <description>Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:51.500-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:18.569-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:33.884-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mesa-libGL-devel is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:91334"/>
          <criterion comment="glx-utils is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:91035"/>
          <criterion comment="mesa-dri-drivers is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:90882"/>
          <criterion comment="mesa is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:91098"/>
          <criterion comment="mesa-libGLU is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:90978"/>
          <criterion comment="mesa-dri-filesystem is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:91074"/>
          <criterion comment="mesa-libGL is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:91340"/>
          <criterion comment="mesa-demos is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:90355"/>
          <criterion comment="mesa-libGLU-devel is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:91277"/>
          <criterion comment="mesa-libOSMesa-devel is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:91243"/>
          <criterion comment="mesa-libOSMesa is earlier than 0:9.0-0.8.el6_4.3" test_ref="oval:org.mitre.oval:tst:91215"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21212" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0052: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0052-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0052.html"/>
        <reference source="CESA" ref_id="CESA-2012:0052"/>
        <reference source="CVE" ref_id="CVE-2012-0056" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0056.html"/>
        <description>The mem_write function in Linux kernel 2.6.39 and other versions, when ASLR is disabled, does not properly check permissions when writing to /proc/&lt;pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:53.372-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:38.226-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:57.820-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92720"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92749"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92462"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92337"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:91814"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92657"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92213"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92597"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92038"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92288"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92033"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.4.1.el6" test_ref="oval:org.mitre.oval:tst:92588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21207" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0069: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0069-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0069.html"/>
        <reference source="CESA" ref_id="CESA-2012:0069"/>
        <reference source="CVE" ref_id="CVE-2011-4815" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4815.html"/>
        <description>Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:02.376-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:37.980-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:57.533-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ruby is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:92589"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:92830"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:92817"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:92593"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:92713"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:92485"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:92869"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:91868"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-4.el6_2" test_ref="oval:org.mitre.oval:tst:92750"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21206" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:1806: samba and samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1806-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1806.html"/>
        <reference source="CESA" ref_id="CESA-2013:1806"/>
        <reference source="CVE" ref_id="CVE-2013-4408" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4408.html"/>
        <reference source="CVE" ref_id="CVE-2013-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4475.html"/>
        <description>Samba 3.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:29.692-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:17.804-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:33.480-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba3x is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91989"/>
            <criterion comment="samba3x-common is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91717"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91982"/>
            <criterion comment="samba3x-doc is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91851"/>
            <criterion comment="samba3x-swat is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91905"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91785"/>
            <criterion comment="samba3x-client is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91820"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.138.el5_10" test_ref="oval:org.mitre.oval:tst:91804"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-common is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91929"/>
            <criterion comment="samba is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91999"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91962"/>
            <criterion comment="samba-winbind is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91864"/>
            <criterion comment="samba-client is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91917"/>
            <criterion comment="samba-doc is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91457"/>
            <criterion comment="libsmbclient is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91741"/>
            <criterion comment="samba-swat is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91891"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91974"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91121"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91858"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.6.9-167.el6_5" test_ref="oval:org.mitre.oval:tst:91773"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21205" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1156: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1156-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1156.html"/>
        <reference source="CESA" ref_id="CESA-2013:1156"/>
        <reference source="CVE" ref_id="CVE-2013-1896" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1896.html"/>
        <description>mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:20.764-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:17.627-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:33.300-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="mod_ssl is earlier than 1:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:91377"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:91527"/>
            <criterion comment="httpd is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:91204"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:91458"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-29.el6_4" test_ref="oval:org.mitre.oval:tst:91572"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="mod_ssl is earlier than 1:2.2.15-29.el6.centos" test_ref="oval:org.mitre.oval:tst:91695"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-29.el6.centos" test_ref="oval:org.mitre.oval:tst:91753"/>
            <criterion comment="httpd is earlier than 0:2.2.15-29.el6.centos" test_ref="oval:org.mitre.oval:tst:92192"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-29.el6.centos" test_ref="oval:org.mitre.oval:tst:91949"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.15-29.el6.centos" test_ref="oval:org.mitre.oval:tst:92197"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="mod_ssl is earlier than 1:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:90720"/>
            <criterion comment="httpd is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:90684"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:91517"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-82.el5_9" test_ref="oval:org.mitre.oval:tst:91633"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="mod_ssl is earlier than 1:2.2.3-82.el5.centos" test_ref="oval:org.mitre.oval:tst:91566"/>
            <criterion comment="httpd is earlier than 0:2.2.3-82.el5.centos" test_ref="oval:org.mitre.oval:tst:92055"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-82.el5.centos" test_ref="oval:org.mitre.oval:tst:91598"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-82.el5.centos" test_ref="oval:org.mitre.oval:tst:91791"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21204" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1418: libtar security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtar</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1418-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1418.html"/>
        <reference source="CESA" ref_id="CESA-2013:1418"/>
        <reference source="CVE" ref_id="CVE-2013-4390" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4390.html"/>
        <description>Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundle before 1.1.4 in Apache Sling allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the resource parameter, related to "a custom login form and XSS."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:50.633-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:17.500-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:33.192-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libtar-devel is earlier than 0:1.2.11-17.el6_4.1" test_ref="oval:org.mitre.oval:tst:91612"/>
          <criterion comment="libtar is earlier than 0:1.2.11-17.el6_4.1" test_ref="oval:org.mitre.oval:tst:91758"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21201" version="187" class="patch">
      <metadata>
        <title>RHSA-2013:0825: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0825-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0825.html"/>
        <reference source="CVE" ref_id="CVE-2013-2728" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2728.html"/>
        <reference source="CVE" ref_id="CVE-2013-3324" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3324.html"/>
        <reference source="CVE" ref_id="CVE-2013-3325" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3325.html"/>
        <reference source="CVE" ref_id="CVE-2013-3326" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3326.html"/>
        <reference source="CVE" ref_id="CVE-2013-3327" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3327.html"/>
        <reference source="CVE" ref_id="CVE-2013-3328" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3328.html"/>
        <reference source="CVE" ref_id="CVE-2013-3329" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3329.html"/>
        <reference source="CVE" ref_id="CVE-2013-3330" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3330.html"/>
        <reference source="CVE" ref_id="CVE-2013-3331" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3331.html"/>
        <reference source="CVE" ref_id="CVE-2013-3332" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3332.html"/>
        <reference source="CVE" ref_id="CVE-2013-3333" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3333.html"/>
        <reference source="CVE" ref_id="CVE-2013-3334" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3334.html"/>
        <reference source="CVE" ref_id="CVE-2013-3335" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3335.html"/>
        <description>Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on Android 4.x; Adobe AIR before 3.7.0.1860; and Adobe AIR SDK &amp; Compiler before 3.7.0.1860 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2728, CVE-2013-3324, CVE-2013-3325, CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331, CVE-2013-3332, CVE-2013-3333, and CVE-2013-3334.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:56.853-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:17.008-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:32.701-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21201 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:11.451-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:48.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.285-1.el5" test_ref="oval:org.mitre.oval:tst:137786"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.285-1.el6" test_ref="oval:org.mitre.oval:tst:90762"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21199" version="354" class="patch">
      <metadata>
        <title>RHSA-2012:1391: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1391-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1391.html"/>
        <reference source="CVE" ref_id="CVE-2012-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1531.html"/>
        <reference source="CVE" ref_id="CVE-2012-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1532.html"/>
        <reference source="CVE" ref_id="CVE-2012-1533" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1533.html"/>
        <reference source="CVE" ref_id="CVE-2012-3143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3143.html"/>
        <reference source="CVE" ref_id="CVE-2012-3159" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3159.html"/>
        <reference source="CVE" ref_id="CVE-2012-3216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3216.html"/>
        <reference source="CVE" ref_id="CVE-2012-4416" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4416.html"/>
        <reference source="CVE" ref_id="CVE-2012-5067" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5067.html"/>
        <reference source="CVE" ref_id="CVE-2012-5068" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5068.html"/>
        <reference source="CVE" ref_id="CVE-2012-5069" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5069.html"/>
        <reference source="CVE" ref_id="CVE-2012-5070" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5070.html"/>
        <reference source="CVE" ref_id="CVE-2012-5071" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5071.html"/>
        <reference source="CVE" ref_id="CVE-2012-5072" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5072.html"/>
        <reference source="CVE" ref_id="CVE-2012-5073" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5073.html"/>
        <reference source="CVE" ref_id="CVE-2012-5074" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5074.html"/>
        <reference source="CVE" ref_id="CVE-2012-5075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5075.html"/>
        <reference source="CVE" ref_id="CVE-2012-5076" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5076.html"/>
        <reference source="CVE" ref_id="CVE-2012-5077" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5077.html"/>
        <reference source="CVE" ref_id="CVE-2012-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5079.html"/>
        <reference source="CVE" ref_id="CVE-2012-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5081.html"/>
        <reference source="CVE" ref_id="CVE-2012-5083" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5083.html"/>
        <reference source="CVE" ref_id="CVE-2012-5084" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5084.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2012-5086" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5086.html"/>
        <reference source="CVE" ref_id="CVE-2012-5087" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5087.html"/>
        <reference source="CVE" ref_id="CVE-2012-5088" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5088.html"/>
        <reference source="CVE" ref_id="CVE-2012-5089" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5089.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:13.660-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:36.720-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:55.934-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94181"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94834"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94494"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94722"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94790"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.9-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:94611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21198" version="367" class="patch">
      <metadata>
        <title>RHSA-2013:1505: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1505-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1505.html"/>
        <reference source="CESA" ref_id="CESA-2013:1505"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:59.794-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:16.183-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:31.524-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:91677"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:91640"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:91221"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:91987"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.65.1.11.14.el6_4" test_ref="oval:org.mitre.oval:tst:91812"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:91042"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:91138"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:91518"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:91705"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.42.1.11.14.el5_10" test_ref="oval:org.mitre.oval:tst:91048"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21196" version="383" class="patch">
      <metadata>
        <title>RHSA-2013:1081: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1081-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1081.html"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2464.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <reference source="CVE" ref_id="CVE-2013-3009" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3009.html"/>
        <reference source="CVE" ref_id="CVE-2013-3011" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3011.html"/>
        <reference source="CVE" ref_id="CVE-2013-3012" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3012.html"/>
        <reference source="CVE" ref_id="CVE-2013-3743" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3743.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:59.642-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:15.197-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:30.304-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21196 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:09.838-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:45.901-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:136979"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137606"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137750"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137644"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137105"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137367"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137826"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.3-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137281"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91311"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91360"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90615"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91553"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91535"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91433"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.3-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90774"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21195" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0983: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0983-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0983.html"/>
        <reference source="CESA" ref_id="CESA-2013:0983"/>
        <reference source="CVE" ref_id="CVE-2013-2174" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2174.html"/>
        <description>Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:03.074-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:15.083-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:30.187-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="curl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:91403"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:91169"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-37.el6_4" test_ref="oval:org.mitre.oval:tst:91055"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="curl is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:91095"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-17.el5_9" test_ref="oval:org.mitre.oval:tst:91111"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21193" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:1803: libjpeg-turbo security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libjpeg-turbo</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1803-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1803.html"/>
        <reference source="CESA" ref_id="CESA-2013:1803"/>
        <reference source="CVE" ref_id="CVE-2013-6629" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6629.html"/>
        <reference source="CVE" ref_id="CVE-2013-6630" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6630.html"/>
        <description>The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:45.073-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:14.961-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:30.003-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libjpeg-turbo is earlier than 0:1.2.1-3.el6_5" test_ref="oval:org.mitre.oval:tst:91381"/>
          <criterion comment="libjpeg-turbo-static is earlier than 0:1.2.1-3.el6_5" test_ref="oval:org.mitre.oval:tst:91945"/>
          <criterion comment="libjpeg-turbo-devel is earlier than 0:1.2.1-3.el6_5" test_ref="oval:org.mitre.oval:tst:91505"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21192" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:0059: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0059-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0059.html"/>
        <reference source="CESA" ref_id="CESA-2012:0059"/>
        <reference source="CVE" ref_id="CVE-2011-4108" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4108.html"/>
        <reference source="CVE" ref_id="CVE-2011-4576" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4576.html"/>
        <reference source="CVE" ref_id="CVE-2011-4577" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4577.html"/>
        <reference source="CVE" ref_id="CVE-2011-4619" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4619.html"/>
        <description>The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:36.571-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:36.410-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:55.369-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:92781"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:92490"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:92400"/>
          <criterion comment="openssl is earlier than 0:1.0.0-20.el6_2.1" test_ref="oval:org.mitre.oval:tst:92565"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21188" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0050: qemu-kvm security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0050-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0050.html"/>
        <reference source="CESA" ref_id="CESA-2012:0050"/>
        <reference source="CVE" ref_id="CVE-2012-0029" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0029.html"/>
        <description>Heap-based buffer overflow in the process_tx_desc function in the e1000 emulation (hw/e1000.c) in qemu-kvm 0.12, and possibly other versions, allows guest OS users to cause a denial of service (QEMU crash) and possibly execute arbitrary code via crafted legacy mode packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:36.747-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:35.973-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:54.754-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.209.el6_2.4" test_ref="oval:org.mitre.oval:tst:92768"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.209.el6_2.4" test_ref="oval:org.mitre.oval:tst:92654"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.209.el6_2.4" test_ref="oval:org.mitre.oval:tst:92669"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21187" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0143: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0143-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0143.html"/>
        <reference source="CESA" ref_id="CESA-2012:0143"/>
        <reference source="CVE" ref_id="CVE-2011-3026" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3026.html"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:38.146-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:35.846-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:54.603-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el6_2" test_ref="oval:org.mitre.oval:tst:92955"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el6_2" test_ref="oval:org.mitre.oval:tst:92950"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el6.centos" test_ref="oval:org.mitre.oval:tst:94918"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el6.centos" test_ref="oval:org.mitre.oval:tst:95011"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-2.el5_7" test_ref="oval:org.mitre.oval:tst:93029"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-2.el5_7" test_ref="oval:org.mitre.oval:tst:92882"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21183" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1473: spice-server security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>spice-server</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1473-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1473.html"/>
        <reference source="CESA" ref_id="CESA-2013:1473"/>
        <reference source="CVE" ref_id="CVE-2013-4282" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4282.html"/>
        <description>Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:44.621-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:14.770-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:29.809-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="spice-server is earlier than 0:0.12.0-12.el6_4.5" test_ref="oval:org.mitre.oval:tst:91112"/>
          <criterion comment="spice-server-devel is earlier than 0:0.12.0-12.el6_4.5" test_ref="oval:org.mitre.oval:tst:91713"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21182" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1119: 389-ds-base security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1119-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1119.html"/>
        <reference source="CESA" ref_id="CESA-2013:1119"/>
        <reference source="CVE" ref_id="CVE-2013-2219" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2219.html"/>
        <description>The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:49.526-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:14.681-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:29.693-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-20.el6_4" test_ref="oval:org.mitre.oval:tst:91577"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-20.el6_4" test_ref="oval:org.mitre.oval:tst:90655"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-20.el6_4" test_ref="oval:org.mitre.oval:tst:91020"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21181" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0697: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0697-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0697.html"/>
        <reference source="CESA" ref_id="CESA-2013:0697"/>
        <reference source="CVE" ref_id="CVE-2013-0788" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0788.html"/>
        <reference source="CVE" ref_id="CVE-2013-0793" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0793.html"/>
        <reference source="CVE" ref_id="CVE-2013-0795" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0795.html"/>
        <reference source="CVE" ref_id="CVE-2013-0796" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0796.html"/>
        <reference source="CVE" ref_id="CVE-2013-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0800.html"/>
        <description>Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:10.058-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:14.485-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:29.501-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:90367"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92270"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:90740"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.5-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92017"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21177" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:1144: nss, nss-util, nss-softokn, and nspr security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-softokn</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1144-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1144.html"/>
        <reference source="CESA" ref_id="CESA-2013:1144"/>
        <reference source="CVE" ref_id="CVE-2013-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0791.html"/>
        <reference source="CVE" ref_id="CVE-2013-1620" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1620.html"/>
        <description>The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:31.728-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:13.536-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:27.978-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nspr is earlier than 0:4.9.5-2.el6_4" test_ref="oval:org.mitre.oval:tst:91459"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.5-2.el6_4" test_ref="oval:org.mitre.oval:tst:91028"/>
          <criterion comment="nss-softokn-freebl is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:91178"/>
          <criterion comment="nss-softokn-freebl-devel is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:91093"/>
          <criterion comment="nss-softokn-devel is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:91376"/>
          <criterion comment="nss-softokn is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:91389"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.14.3-4.el6_4" test_ref="oval:org.mitre.oval:tst:91596"/>
          <criterion comment="nss-tools is earlier than 0:3.14.3-4.el6_4" test_ref="oval:org.mitre.oval:tst:91318"/>
          <criterion comment="nss-devel is earlier than 0:3.14.3-4.el6_4" test_ref="oval:org.mitre.oval:tst:91574"/>
          <criterion comment="nss is earlier than 0:3.14.3-4.el6_4" test_ref="oval:org.mitre.oval:tst:91350"/>
          <criterion comment="nss-sysinit is earlier than 0:3.14.3-4.el6_4" test_ref="oval:org.mitre.oval:tst:91492"/>
          <criterion comment="nss-util-devel is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:90920"/>
          <criterion comment="nss-util is earlier than 0:3.14.3-3.el6_4" test_ref="oval:org.mitre.oval:tst:91186"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21175" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1192: spice-server security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>spice-server</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1192-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1192.html"/>
        <reference source="CESA" ref_id="CESA-2013:1192"/>
        <reference source="CVE" ref_id="CVE-2013-4130" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4130.html"/>
        <description>The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:52.316-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:13.437-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:27.833-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="spice-server is earlier than 0:0.12.0-12.el6_4.3" test_ref="oval:org.mitre.oval:tst:91622"/>
          <criterion comment="spice-server-devel is earlier than 0:0.12.0-12.el6_4.3" test_ref="oval:org.mitre.oval:tst:91644"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21174" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0714: stunnel security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>stunnel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0714-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0714.html"/>
        <reference source="CESA" ref_id="CESA-2013:0714"/>
        <reference source="CVE" ref_id="CVE-2013-1762" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1762.html"/>
        <description>stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:59.583-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:13.347-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:27.705-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="stunnel is earlier than 0:4.29-3.el6_4" test_ref="oval:org.mitre.oval:tst:90692"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21173" version="675" class="patch">
      <metadata>
        <title>RHSA-2013:1440: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1440-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1440.html"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5775" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5775.html"/>
        <reference source="CVE" ref_id="CVE-2013-5776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5776.html"/>
        <reference source="CVE" ref_id="CVE-2013-5777" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5777.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5787.html"/>
        <reference source="CVE" ref_id="CVE-2013-5788" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5788.html"/>
        <reference source="CVE" ref_id="CVE-2013-5789" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5789.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5800.html"/>
        <reference source="CVE" ref_id="CVE-2013-5801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5801.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5810" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5810.html"/>
        <reference source="CVE" ref_id="CVE-2013-5812" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5812.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5818" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5818.html"/>
        <reference source="CVE" ref_id="CVE-2013-5819" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5819.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5824" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5824.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5831" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5831.html"/>
        <reference source="CVE" ref_id="CVE-2013-5832" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5832.html"/>
        <reference source="CVE" ref_id="CVE-2013-5838" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5838.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5843" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5843.html"/>
        <reference source="CVE" ref_id="CVE-2013-5844" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5844.html"/>
        <reference source="CVE" ref_id="CVE-2013-5846" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5846.html"/>
        <reference source="CVE" ref_id="CVE-2013-5848" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5848.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <reference source="CVE" ref_id="CVE-2013-5851" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5851.html"/>
        <reference source="CVE" ref_id="CVE-2013-5852" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5852.html"/>
        <reference source="CVE" ref_id="CVE-2013-5854" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5854.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:14.739-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:12.178-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:26.074-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91790"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91658"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91609"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91324"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91854"/>
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.45-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91850"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21171" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1090: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1090-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1090.html"/>
        <reference source="CESA" ref_id="CESA-2013:1090"/>
        <reference source="CVE" ref_id="CVE-2013-4073" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4073.html"/>
        <description>The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.0-p247 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:14.387-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:12.043-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:25.912-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91540"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:90988"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91554"/>
            <criterion comment="ruby-static is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91608"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91532"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91265"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91197"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91298"/>
            <criterion comment="ruby is earlier than 0:1.8.7.352-12.el6_4" test_ref="oval:org.mitre.oval:tst:91472"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91512"/>
            <criterion comment="ruby-ri is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91538"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91219"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91547"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91099"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91125"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91358"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91606"/>
            <criterion comment="ruby is earlier than 0:1.8.5-31.el5_9" test_ref="oval:org.mitre.oval:tst:91418"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21169" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0939: xorg-x11-server security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0939-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0939.html"/>
        <reference source="CESA" ref_id="CESA-2012:0939"/>
        <reference source="CVE" ref_id="CVE-2011-4028" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4028.html"/>
        <reference source="CVE" ref_id="CVE-2011-4029" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4029.html"/>
        <description>The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (removed execution permission) via a symlink attack on a temporary lock file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:28.506-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:35.131-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:53.465-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:93372"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:93680"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:93787"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:94031"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:93956"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:93764"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:93888"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:93710"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.10.6-1.el6" test_ref="oval:org.mitre.oval:tst:94002"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.10.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94866"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.10.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94956"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.10.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94896"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.10.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94891"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.10.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94791"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.10.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94407"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.10.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94958"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.10.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:95046"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.10.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94525"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21168" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1273: spice-gtk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>spice-gtk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1273-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1273.html"/>
        <reference source="CESA" ref_id="CESA-2013:1273"/>
        <reference source="CVE" ref_id="CVE-2013-4324" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4324.html"/>
        <description>spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:27.059-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:11.939-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:25.779-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="spice-gtk-devel is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:91489"/>
          <criterion comment="spice-glib-devel is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:91611"/>
          <criterion comment="spice-gtk-python is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:91651"/>
          <criterion comment="spice-gtk is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:91317"/>
          <criterion comment="spice-gtk-tools is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:91328"/>
          <criterion comment="spice-glib is earlier than 0:0.14-7.el6_4.3" test_ref="oval:org.mitre.oval:tst:91475"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21167" version="115" class="patch">
      <metadata>
        <title>RHSA-2013:1476: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1476-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1476.html"/>
        <reference source="CESA" ref_id="CESA-2013:1476"/>
        <reference source="CVE" ref_id="CVE-2013-5590" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5590.html"/>
        <reference source="CVE" ref_id="CVE-2013-5595" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5595.html"/>
        <reference source="CVE" ref_id="CVE-2013-5597" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5597.html"/>
        <reference source="CVE" ref_id="CVE-2013-5599" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5599.html"/>
        <reference source="CVE" ref_id="CVE-2013-5600" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5600.html"/>
        <reference source="CVE" ref_id="CVE-2013-5601" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5601.html"/>
        <reference source="CVE" ref_id="CVE-2013-5602" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5602.html"/>
        <reference source="CVE" ref_id="CVE-2013-5604" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5604.html"/>
        <description>The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly initialize data, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow and application crash) via crafted documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:42.634-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:11.625-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:25.457-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:91643"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:91926"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:91188"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91614"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92245"/>
            <criterion comment="firefox is earlier than 0:17.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91980"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:91448"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:91667"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.10-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92269"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:91849"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21165" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0433: xorg-x11-server-utils security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>xorg-x11-server-utils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0433-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0433.html"/>
        <reference source="CVE" ref_id="CVE-2011-0465" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0465.html"/>
        <reference source="CESA-2011:0433" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017321.html" ref_id="CESA-2011:0433-CentOS 5"/>
        <description>xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:32.864-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:34.804-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:53.025-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21165 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:32.435-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:45.287-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="xorg-x11-server-utils is earlier than 0:7.1-5.el5_6.1" test_ref="oval:org.mitre.oval:tst:137349"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="xorg-x11-server-utils is earlier than 0:7.4-15.el6_0.1" test_ref="oval:org.mitre.oval:tst:97338"/>
            <criterion comment="xorg-x11-server-utils-debuginfo is earlier than 0:7.4-15.el6_0.1" test_ref="oval:org.mitre.oval:tst:137539"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21162" version="6" class="patch">
      <metadata>
        <title>RHSA-2012:0688: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0688-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0688.html"/>
        <reference source="CVE" ref_id="CVE-2012-0779" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0779.html"/>
        <description>Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on Android 2.x and 3.x; and before 11.1.115.8 on Android 4.x allows remote attackers to execute arbitrary code via a crafted file, related to an "object confusion vulnerability," as exploited in the wild in May 2012.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:28.902-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:34.481-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:52.637-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21162 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:32.600-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:44.993-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.19-1.el5" test_ref="oval:org.mitre.oval:tst:137903"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.19-1.el6" test_ref="oval:org.mitre.oval:tst:93460"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21160" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:1085: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:1085-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-1085.html"/>
        <reference source="CVE" ref_id="CVE-2011-0226" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0226.html"/>
        <description>Integer signedness error in psaux/t1decode.c in FreeType before 2.4.6, as used in CoreGraphics in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Type 1 font in a PDF document, as exploited in the wild in July 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:36:53.688-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:34.393-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:52.535-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.6" test_ref="oval:org.mitre.oval:tst:98264"/>
          <criterion comment="freetype is earlier than 0:2.3.11-6.el6_1.6" test_ref="oval:org.mitre.oval:tst:97734"/>
          <criterion comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.6" test_ref="oval:org.mitre.oval:tst:98143"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21159" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0407: logrotate security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>logrotate</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0407-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0407.html"/>
        <reference source="CVE" ref_id="CVE-2011-1098" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1098.html"/>
        <reference source="CVE" ref_id="CVE-2011-1154" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1154.html"/>
        <reference source="CVE" ref_id="CVE-2011-1155" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1155.html"/>
        <description>The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:53.185-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:34.266-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:52.358-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="logrotate is earlier than 0:3.7.8-12.el6_0.1" test_ref="oval:org.mitre.oval:tst:97430"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21158" version="6" class="patch">
      <metadata>
        <title>RHSA-2013:1813: php53 and php security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php53</product>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1813-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1813.html"/>
        <reference source="CESA" ref_id="CESA-2013:1813"/>
        <reference source="CVE" ref_id="CVE-2013-6420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6420.html"/>
        <description>The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:23.515-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:11.254-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:24.722-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21158 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:39.681-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:28.749-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php53-intl is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91708"/>
            <criterion comment="php53-pdo is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91818"/>
            <criterion comment="php53-gd is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91675"/>
            <criterion comment="php53 is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:92006"/>
            <criterion comment="php53-pspell is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91907"/>
            <criterion comment="php53-common is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91807"/>
            <criterion comment="php53-devel is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91573"/>
            <criterion comment="php53-mysql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91978"/>
            <criterion comment="php53-process is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91194"/>
            <criterion comment="php53-ldap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91256"/>
            <criterion comment="php53-cli is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91010"/>
            <criterion comment="php53-bcmath is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91919"/>
            <criterion comment="php53-dba is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91672"/>
            <criterion comment="php53-mbstring is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91884"/>
            <criterion comment="php53-snmp is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91595"/>
            <criterion comment="php53-odbc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91558"/>
            <criterion comment="php53-pgsql is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91954"/>
            <criterion comment="php53-xml is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91956"/>
            <criterion comment="php53-imap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91650"/>
            <criterion comment="php53-xmlrpc is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91774"/>
            <criterion comment="php53-soap is earlier than 0:5.3.3-22.el5_10" test_ref="oval:org.mitre.oval:tst:91829"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-common is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91380"/>
            <criterion comment="php-process is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91209"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91878"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91165"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91902"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91681"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91500"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91348"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91828"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91217"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91939"/>
            <criterion comment="php-embedded is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91407"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91537"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91262"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91883"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91957"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91967"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91971"/>
            <criterion comment="php is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91688"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91840"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91772"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91950"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:92010"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91323"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91017"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91936"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-27.el6_5" test_ref="oval:org.mitre.oval:tst:91345"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21154" version="198" class="patch">
      <metadata>
        <title>RHSA-2012:0509: wireshark security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0509-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0509.html"/>
        <reference source="CESA" ref_id="CESA-2012:0509"/>
        <reference source="CVE" ref_id="CVE-2011-1143" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1143.html"/>
        <reference source="CVE" ref_id="CVE-2011-1590" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1590.html"/>
        <reference source="CVE" ref_id="CVE-2011-1957" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1957.html"/>
        <reference source="CVE" ref_id="CVE-2011-1958" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1958.html"/>
        <reference source="CVE" ref_id="CVE-2011-1959" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1959.html"/>
        <reference source="CVE" ref_id="CVE-2011-2174" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2174.html"/>
        <reference source="CVE" ref_id="CVE-2011-2175" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2175.html"/>
        <reference source="CVE" ref_id="CVE-2011-2597" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2597.html"/>
        <reference source="CVE" ref_id="CVE-2011-2698" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2698.html"/>
        <reference source="CVE" ref_id="CVE-2011-4102" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4102.html"/>
        <reference source="CVE" ref_id="CVE-2012-0041" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0041.html"/>
        <reference source="CVE" ref_id="CVE-2012-0042" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0042.html"/>
        <reference source="CVE" ref_id="CVE-2012-0066" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0066.html"/>
        <reference source="CVE" ref_id="CVE-2012-0067" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0067.html"/>
        <reference source="CVE" ref_id="CVE-2012-1595" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1595.html"/>
        <description>The pcap_process_pseudo_header function in wiretap/pcap-common.c in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (application crash) via a WTAP_ENCAP_ERF file containing an Extension or Multi-Channel header with an invalid pseudoheader size, related to the pcap and pcap-ng file parsers.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:14.544-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:33.376-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:51.401-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="wireshark is earlier than 0:1.2.15-2.el6_2.1" test_ref="oval:org.mitre.oval:tst:93269"/>
          <criterion comment="wireshark-devel is earlier than 0:1.2.15-2.el6_2.1" test_ref="oval:org.mitre.oval:tst:93209"/>
          <criterion comment="wireshark-gnome is earlier than 0:1.2.15-2.el6_2.1" test_ref="oval:org.mitre.oval:tst:92845"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21151" version="649" class="patch">
      <metadata>
        <title>RHSA-2013:1507: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1507-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1507.html"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4041" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4041.html"/>
        <reference source="CVE" ref_id="CVE-2013-5372" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5372.html"/>
        <reference source="CVE" ref_id="CVE-2013-5375" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5375.html"/>
        <reference source="CVE" ref_id="CVE-2013-5456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5456.html"/>
        <reference source="CVE" ref_id="CVE-2013-5457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5457.html"/>
        <reference source="CVE" ref_id="CVE-2013-5458" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5458.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5776.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5787.html"/>
        <reference source="CVE" ref_id="CVE-2013-5788" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5788.html"/>
        <reference source="CVE" ref_id="CVE-2013-5789" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5789.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5800.html"/>
        <reference source="CVE" ref_id="CVE-2013-5801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5801.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5812" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5812.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5818" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5818.html"/>
        <reference source="CVE" ref_id="CVE-2013-5819" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5819.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5824" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5824.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5831" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5831.html"/>
        <reference source="CVE" ref_id="CVE-2013-5832" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5832.html"/>
        <reference source="CVE" ref_id="CVE-2013-5838" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5838.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5843" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5843.html"/>
        <reference source="CVE" ref_id="CVE-2013-5848" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5848.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <reference source="CVE" ref_id="CVE-2013-5851" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5851.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:37.184-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:09.676-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:22.702-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21151 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:13.148-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:41.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137797"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137720"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137697"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137743"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137132"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.0-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137683"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91787"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91811"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91756"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91399"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91679"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91931"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21149" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0696: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0696-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0696.html"/>
        <reference source="CESA" ref_id="CESA-2013:0696"/>
        <reference source="CVE" ref_id="CVE-2013-0788" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0788.html"/>
        <reference source="CVE" ref_id="CVE-2013-0793" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0793.html"/>
        <reference source="CVE" ref_id="CVE-2013-0795" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0795.html"/>
        <reference source="CVE" ref_id="CVE-2013-0796" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0796.html"/>
        <reference source="CVE" ref_id="CVE-2013-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0800.html"/>
        <description>Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to execute arbitrary code via crafted values that trigger attempted use of a (1) negative box boundary or (2) negative box size, leading to an out-of-bounds write operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:04.142-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:09.458-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:22.423-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:90804"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:91171"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:91004"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92148"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92273"/>
            <criterion comment="firefox is earlier than 0:17.0.5-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92059"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:90904"/>
            <criterion comment="xulrunner is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:90848"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.5-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92256"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:91043"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21148" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0272: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0272-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0272.html"/>
        <reference source="CESA" ref_id="CESA-2013:0272"/>
        <reference source="CVE" ref_id="CVE-2013-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0775.html"/>
        <reference source="CVE" ref_id="CVE-2013-0776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0776.html"/>
        <reference source="CVE" ref_id="CVE-2013-0780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0780.html"/>
        <reference source="CVE" ref_id="CVE-2013-0782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0782.html"/>
        <reference source="CVE" ref_id="CVE-2013-0783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0783.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:31.039-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:09.280-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:22.150-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:89752"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91960"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:90228"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91894"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21147" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0774: libguestfs security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libguestfs</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0774-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0774.html"/>
        <reference source="CESA" ref_id="CESA-2012:0774"/>
        <reference source="CVE" ref_id="CVE-2012-2690" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2690.html"/>
        <description>virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:33.069-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:33.052-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:51.003-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libguestfs-javadoc is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93800"/>
          <criterion comment="libguestfs-java-devel is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93696"/>
          <criterion comment="libguestfs-java is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93604"/>
          <criterion comment="perl-Sys-Guestfs is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93502"/>
          <criterion comment="libguestfs is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93674"/>
          <criterion comment="ocaml-libguestfs is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93519"/>
          <criterion comment="python-libguestfs is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93733"/>
          <criterion comment="ocaml-libguestfs-devel is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93578"/>
          <criterion comment="libguestfs-devel is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93541"/>
          <criterion comment="libguestfs-tools-c is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:92943"/>
          <criterion comment="ruby-libguestfs is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93612"/>
          <criterion comment="libguestfs-tools is earlier than 1:1.16.19-1.el6" test_ref="oval:org.mitre.oval:tst:93658"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21144" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0502: Core X11 clients security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-apps</product>
          <product>xorg-x11-server-utils</product>
          <product>xorg-x11-utils</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0502-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0502.html"/>
        <reference source="CESA" ref_id="CESA-2013:0502"/>
        <reference source="CVE" ref_id="CVE-2011-2504" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2504.html"/>
        <description>Untrusted search path vulnerability in x11perfcomp in XFree86 x11perf before 1.5.4 allows local users to gain privileges via unspecified Trojan horse code in the current working directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:29.856-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:08.939-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:21.786-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="xorg-x11-utils is earlier than 0:7.5-6.el6" test_ref="oval:org.mitre.oval:tst:90149"/>
          <criterion comment="xorg-x11-server-utils is earlier than 0:7.5-13.el6" test_ref="oval:org.mitre.oval:tst:90552"/>
          <criterion comment="xorg-x11-apps is earlier than 0:7.6-6.el6" test_ref="oval:org.mitre.oval:tst:90240"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21141" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0942: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0942-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0942.html"/>
        <reference source="CESA" ref_id="CESA-2013:0942"/>
        <reference source="CVE" ref_id="CVE-2002-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2002-2443.html"/>
        <description>schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:36.123-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:08.721-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:21.498-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:91146"/>
            <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:90946"/>
            <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:91314"/>
            <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:90910"/>
            <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:90619"/>
            <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:91392"/>
            <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.3" test_ref="oval:org.mitre.oval:tst:91170"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="krb5-server-ldap is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:91346"/>
            <criterion comment="krb5-devel is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:91029"/>
            <criterion comment="krb5-workstation is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:91368"/>
            <criterion comment="krb5-libs is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:90691"/>
            <criterion comment="krb5-server is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:91364"/>
            <criterion comment="krb5 is earlier than 0:1.6.1-70.el5_9.2" test_ref="oval:org.mitre.oval:tst:91177"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21140" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0580: cups security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>cups</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0580-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0580.html"/>
        <reference source="CESA" ref_id="CESA-2013:0580"/>
        <reference source="CVE" ref_id="CVE-2012-5519" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5519.html"/>
        <description>CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0 using certain permissions, which allows local users in the lpadmin group to read or write arbitrary files as root by leveraging the web interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:27.780-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:08.603-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:21.341-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cups-php is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:90751"/>
            <criterion comment="cups-lpd is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:90668"/>
            <criterion comment="cups-devel is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:90645"/>
            <criterion comment="cups is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:90576"/>
            <criterion comment="cups-libs is earlier than 1:1.4.2-50.el6_4.4" test_ref="oval:org.mitre.oval:tst:89883"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cups-devel is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:90213"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:90674"/>
            <criterion comment="cups is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:90732"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-30.el5_9.3" test_ref="oval:org.mitre.oval:tst:90760"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21139" version="143" class="patch">
      <metadata>
        <title>RHSA-2013:0820: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0820-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0820.html"/>
        <reference source="CESA" ref_id="CESA-2013:0820"/>
        <reference source="CVE" ref_id="CVE-2013-0801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0801.html"/>
        <reference source="CVE" ref_id="CVE-2013-1670" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1670.html"/>
        <reference source="CVE" ref_id="CVE-2013-1674" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1674.html"/>
        <reference source="CVE" ref_id="CVE-2013-1675" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1675.html"/>
        <reference source="CVE" ref_id="CVE-2013-1676" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1676.html"/>
        <reference source="CVE" ref_id="CVE-2013-1677" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1677.html"/>
        <reference source="CVE" ref_id="CVE-2013-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1678.html"/>
        <reference source="CVE" ref_id="CVE-2013-1679" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1679.html"/>
        <reference source="CVE" ref_id="CVE-2013-1680" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1680.html"/>
        <reference source="CVE" ref_id="CVE-2013-1681" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1681.html"/>
        <description>Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:51.795-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:08.228-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:20.889-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:17.0.6-1.el6_4" test_ref="oval:org.mitre.oval:tst:90992"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:91069"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:91051"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:17.0.6-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92136"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-2.el6.centos" test_ref="oval:org.mitre.oval:tst:92243"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-2.el6.centos" test_ref="oval:org.mitre.oval:tst:92067"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:91223"/>
            <criterion comment="xulrunner is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:90971"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.6-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92150"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:90967"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21138" version="6" class="patch">
      <metadata>
        <title>RHSA-2011:0197: postgresql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0197-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0197.html"/>
        <reference source="CVE" ref_id="CVE-2010-4015" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4015.html"/>
        <reference source="CESA-2011:0197" ref_url="http://lists.centos.org/pipermail/centos-announce/2011-April/017381.html" ref_id="CESA-2011:0197-CentOS 5"/>
        <description>Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via integers with a large number of digits to unspecified functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:38:24.319-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:32.783-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:50.677-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21138 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:26.252-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:41.060-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 and CentOS Linux 5 release section">
          <criteria operator="OR" comment="Operation system section">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql-devel is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137871"/>
            <criterion comment="postgresql-pl is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137916"/>
            <criterion comment="postgresql-server is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137824"/>
            <criterion comment="postgresql-test is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137836"/>
            <criterion comment="postgresql is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137633"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137009"/>
            <criterion comment="postgresql-docs is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137807"/>
            <criterion comment="postgresql-libs is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137977"/>
            <criterion comment="postgresql-python is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137685"/>
            <criterion comment="postgresql-tcl is earlier than 0:8.1.23-1.el5_6.1" test_ref="oval:org.mitre.oval:tst:137579"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="postgresql is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97035"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96874"/>
            <criterion comment="postgresql-debuginfo is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:137733"/>
            <criterion comment="postgresql-devel is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97279"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97353"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97332"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97250"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:97359"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96952"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96754"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.7-1.el6_0.1" test_ref="oval:org.mitre.oval:tst:96635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21137" version="5" class="patch">
      <metadata>
        <title>RHSA-2012:0683: bind-dyndb-ldap security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind-dyndb-ldap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0683-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0683.html"/>
        <reference source="CESA" ref_id="CESA-2012:0683"/>
        <reference source="CVE" ref_id="CVE-2012-2134" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2134.html"/>
        <description>The handle_connection_error function in ldap_helper.c in bind-dyndb-ldap before 1.1.0rc1 does not properly handle LDAP query errors, which allows remote attackers to cause a denial of service (infinite loop and named server hang) via a non-alphabet character in the base DN in an LDAP search DNS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:07.578-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:32.682-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:50.574-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="bind-dyndb-ldap is earlier than 0:0.2.0-7.el6_2.1" test_ref="oval:org.mitre.oval:tst:93439"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21135" version="409" class="patch">
      <metadata>
        <title>RHSA-2013:0957: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0957-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0957.html"/>
        <reference source="CESA" ref_id="CESA-2013:0957"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2445.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2449.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2458" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2458.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2460" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2460.html"/>
        <reference source="CVE" ref_id="CVE-2013-2461" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2461.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:38.908-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:07.899-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:20.467-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.25-2.3.10.3.el6_4" test_ref="oval:org.mitre.oval:tst:90868"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.25-2.3.10.3.el6_4" test_ref="oval:org.mitre.oval:tst:91122"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.25-2.3.10.3.el6_4" test_ref="oval:org.mitre.oval:tst:91411"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.25-2.3.10.3.el6_4" test_ref="oval:org.mitre.oval:tst:90781"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.25-2.3.10.3.el6_4" test_ref="oval:org.mitre.oval:tst:91421"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21134" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1426: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1426-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1426.html"/>
        <reference source="CESA" ref_id="CESA-2013:1426"/>
        <reference source="CVE" ref_id="CVE-2013-4396" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4396.html"/>
        <description>Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:55.983-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:07.713-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:20.278-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:90815"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91616"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91244"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91310"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91578"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91636"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91337"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91709"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-11.1.el6_4.2" test_ref="oval:org.mitre.oval:tst:91743"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92267"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92231"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92109"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92275"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92099"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91981"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92172"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91297"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-11.1.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91710"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91617"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91845"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91870"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91038"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91885"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91663"/>
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:91831"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.el5_10.1" test_ref="oval:org.mitre.oval:tst:90902"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21133" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0321: cvs security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>cvs</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0321-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0321.html"/>
        <reference source="CESA" ref_id="CESA-2012:0321"/>
        <reference source="CVE" ref_id="CVE-2012-0804" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0804.html"/>
        <description>Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:47.980-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:32.579-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:50.454-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="cvs-inetd is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:92451"/>
            <criterion comment="cvs is earlier than 0:1.11.22-11.el5_8.1" test_ref="oval:org.mitre.oval:tst:92896"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="cvs is earlier than 0:1.11.23-11.el6_2.1" test_ref="oval:org.mitre.oval:tst:93081"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21132" version="61" class="patch">
      <metadata>
        <title>RHSA-2013:1850: openjpeg security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>openjpeg</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1850-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1850.html"/>
        <reference source="CESA" ref_id="CESA-2013:1850"/>
        <reference source="CVE" ref_id="CVE-2013-1447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1447.html"/>
        <reference source="CVE" ref_id="CVE-2013-6045" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6045.html"/>
        <reference source="CVE" ref_id="CVE-2013-6052" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6052.html"/>
        <reference source="CVE" ref_id="CVE-2013-6054" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6054.html"/>
        <description>Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:24.728-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:07.491-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:20.042-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21132 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:41.074-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:26.527-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openjpeg is earlier than 0:1.3-10.el6_5" test_ref="oval:org.mitre.oval:tst:91739"/>
          <criterion comment="openjpeg-libs is earlier than 0:1.3-10.el6_5" test_ref="oval:org.mitre.oval:tst:91696"/>
          <criterion comment="openjpeg-devel is earlier than 0:1.3-10.el6_5" test_ref="oval:org.mitre.oval:tst:91541"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21131" version="607" class="patch">
      <metadata>
        <title>RHSA-2013:1060: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1060-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1060.html"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2400" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2400.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2437.html"/>
        <reference source="CVE" ref_id="CVE-2013-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2442.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2449.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2451.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2458" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2458.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2460" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2460.html"/>
        <reference source="CVE" ref_id="CVE-2013-2462" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2462.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2464.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2466" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2466.html"/>
        <reference source="CVE" ref_id="CVE-2013-2468" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2468.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <reference source="CVE" ref_id="CVE-2013-3006" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3006.html"/>
        <reference source="CVE" ref_id="CVE-2013-3007" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3007.html"/>
        <reference source="CVE" ref_id="CVE-2013-3008" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3008.html"/>
        <reference source="CVE" ref_id="CVE-2013-3009" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3009.html"/>
        <reference source="CVE" ref_id="CVE-2013-3010" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3010.html"/>
        <reference source="CVE" ref_id="CVE-2013-3011" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3011.html"/>
        <reference source="CVE" ref_id="CVE-2013-3012" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3012.html"/>
        <reference source="CVE" ref_id="CVE-2013-3744" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3744.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 allows remote attackers to affect availability via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:45.264-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:06.404-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:18.492-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21131 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:10.782-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:37.334-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137681"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137771"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137789"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137793"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137198"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.5.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137716"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91108"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91526"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91054"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91341"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91331"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.5.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:91387"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21130" version="5" class="patch">
      <metadata>
        <title>RHSA-2012:0376: systemtap security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>systemtap</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0376-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0376.html"/>
        <reference source="CESA" ref_id="CESA-2012:0376"/>
        <reference source="CVE" ref_id="CVE-2012-0875" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0875.html"/>
        <description>SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information from kernel memory or cause a denial of service (kernel panic and crash) via vectors related to crafted DWARF data, which triggers a read of an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:21.128-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:32.451-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:50.299-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="systemtap-runtime is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92899"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92917"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92945"/>
            <criterion comment="systemtap is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92914"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92634"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-7.el5_8" test_ref="oval:org.mitre.oval:tst:92523"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="systemtap-runtime is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92849"/>
            <criterion comment="systemtap-testsuite is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92855"/>
            <criterion comment="systemtap-sdt-devel is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92134"/>
            <criterion comment="systemtap is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92853"/>
            <criterion comment="systemtap-grapher is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92615"/>
            <criterion comment="systemtap-initscript is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:93008"/>
            <criterion comment="systemtap-server is earlier than 0:1.6-5.el6_2" test_ref="oval:org.mitre.oval:tst:92097"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21128" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0140: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0140-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0140.html"/>
        <reference source="CESA" ref_id="CESA-2012:0140"/>
        <reference source="CVE" ref_id="CVE-2011-3026" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3026.html"/>
        <description>Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:20.521-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:32.352-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:50.042-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:3.1.18-2.el6_2" test_ref="oval:org.mitre.oval:tst:92569"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:3.1.18-2.el6.centos" test_ref="oval:org.mitre.oval:tst:95013"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21127" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0250: elinks security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>elinks</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0250-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0250.html"/>
        <reference source="CESA" ref_id="CESA-2013:0250"/>
        <reference source="CVE" ref_id="CVE-2012-4545" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4545.html"/>
        <description>The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote servers to authenticate as the client via the delegated credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:51.639-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:06.185-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:18.251-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criterion comment="elinks is earlier than 0:0.12-0.21.pre5.el6_3" test_ref="oval:org.mitre.oval:tst:90393"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="elinks is earlier than 0:0.11.1-8.el5_9" test_ref="oval:org.mitre.oval:tst:90270"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21125" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1282: rtkit security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>rtkit</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1282-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1282.html"/>
        <reference source="CESA" ref_id="CESA-2013:1282"/>
        <reference source="CVE" ref_id="CVE-2013-4326" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4326.html"/>
        <description>RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:36.885-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:06.088-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:18.139-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="rtkit is earlier than 0:0.5-2.el6_4" test_ref="oval:org.mitre.oval:tst:91295"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21124" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0271: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>devhelp</product>
          <product>firefox</product>
          <product>xulrunner</product>
          <product>yelp</product>
          <product>libproxy</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0271-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0271.html"/>
        <reference source="CESA" ref_id="CESA-2013:0271"/>
        <reference source="CVE" ref_id="CVE-2013-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0775.html"/>
        <reference source="CVE" ref_id="CVE-2013-0776" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0776.html"/>
        <reference source="CVE" ref_id="CVE-2013-0780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0780.html"/>
        <reference source="CVE" ref_id="CVE-2013-0782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0782.html"/>
        <reference source="CVE" ref_id="CVE-2013-0783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0783.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey before 2.16 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:40.486-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:05.830-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:17.772-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 and Centos 6 section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="yelp is earlier than 0:2.28.1-17.el6_3" test_ref="oval:org.mitre.oval:tst:90204"/>
            <criterion comment="libproxy-bin is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90392"/>
            <criterion comment="libproxy-mozjs is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:89980"/>
            <criterion comment="libproxy-devel is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90290"/>
            <criterion comment="libproxy-webkit is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90084"/>
            <criterion comment="libproxy is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:89815"/>
            <criterion comment="libproxy-gnome is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90044"/>
            <criterion comment="libproxy-python is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90487"/>
            <criterion comment="libproxy-kde is earlier than 0:0.3.0-4.el6_3" test_ref="oval:org.mitre.oval:tst:90223"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92116"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91241"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92094"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:90337"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:90458"/>
            <criterion comment="firefox is earlier than 0:17.0.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:90216"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="yelp is earlier than 0:2.16.0-30.el5_9" test_ref="oval:org.mitre.oval:tst:90300"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:90387"/>
            <criterion comment="devhelp is earlier than 0:0.12-23.el5_9" test_ref="oval:org.mitre.oval:tst:90258"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:90424"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:90491"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.3-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92139"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:90231"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21121" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0884: libtirpc security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtirpc</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0884-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0884.html"/>
        <reference source="CESA" ref_id="CESA-2013:0884"/>
        <reference source="CVE" ref_id="CVE-2013-1950" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1950.html"/>
        <description>The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind crash) via a Sun RPC request with crafted arguments that trigger a free of an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:55.788-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:05.732-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:17.612-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libtirpc-devel is earlier than 0:0.2.1-6.el6_4" test_ref="oval:org.mitre.oval:tst:91333"/>
          <criterion comment="libtirpc is earlier than 0:0.2.1-6.el6_4" test_ref="oval:org.mitre.oval:tst:91172"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21119" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0827: openswan security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openswan</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0827-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0827.html"/>
        <reference source="CESA" ref_id="CESA-2013:0827"/>
        <reference source="CVE" ref_id="CVE-2013-2053" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2053.html"/>
        <description>Buffer overflow in the atodn function in Openswan before 2.6.39, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records.  NOTE: this might be the same vulnerability as CVE-2013-2052 and CVE-2013-2054.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:28.060-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:05.593-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:17.489-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:91137"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-20.el6_4" test_ref="oval:org.mitre.oval:tst:90925"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openswan is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:90802"/>
            <criterion comment="openswan-doc is earlier than 0:2.6.32-5.el5_9" test_ref="oval:org.mitre.oval:tst:90844"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21117" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0687: pixman security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0687-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0687.html"/>
        <reference source="CESA" ref_id="CESA-2013:0687"/>
        <reference source="CVE" ref_id="CVE-2013-1591" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1591.html"/>
        <description>Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors.  NOTE: this issue might be resultant from an integer overflow in the fast_composite_scaled_bilinear function in pixman-inlines.h, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:16.535-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:05.512-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:17.377-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pixman-devel is earlier than 0:0.26.2-5.el6_4" test_ref="oval:org.mitre.oval:tst:90682"/>
          <criterion comment="pixman is earlier than 0:0.26.2-5.el6_4" test_ref="oval:org.mitre.oval:tst:90977"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21116" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0646: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0646-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0646.html"/>
        <reference source="CESA" ref_id="CESA-2013:0646"/>
        <reference source="CVE" ref_id="CVE-2013-0272" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0272.html"/>
        <reference source="CVE" ref_id="CVE-2013-0273" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0273.html"/>
        <reference source="CVE" ref_id="CVE-2013-0274" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0274.html"/>
        <description>upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:28.816-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:05.346-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:17.156-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90912"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90937"/>
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90641"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90825"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90779"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:91023"/>
            <criterion comment="finch is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90964"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:91024"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90702"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90976"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90965"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90432"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90855"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90234"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:91050"/>
            <criterion comment="finch is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90540"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90942"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90127"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-17.el5_9.1" test_ref="oval:org.mitre.oval:tst:90646"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21113" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0276: libvirt security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0276-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0276.html"/>
        <reference source="CESA" ref_id="CESA-2013:0276"/>
        <reference source="CVE" ref_id="CVE-2012-3411" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3411.html"/>
        <description>Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed DNS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:29.772-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:05.023-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:16.787-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.10.2-18.el6" test_ref="oval:org.mitre.oval:tst:90406"/>
          <criterion comment="libvirt-python is earlier than 0:0.10.2-18.el6" test_ref="oval:org.mitre.oval:tst:90244"/>
          <criterion comment="libvirt-client is earlier than 0:0.10.2-18.el6" test_ref="oval:org.mitre.oval:tst:90249"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.10.2-18.el6" test_ref="oval:org.mitre.oval:tst:89576"/>
          <criterion comment="libvirt is earlier than 0:0.10.2-18.el6" test_ref="oval:org.mitre.oval:tst:90501"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21111" version="327" class="patch">
      <metadata>
        <title>RHSA-2013:0823: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0823-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0823.html"/>
        <reference source="CVE" ref_id="CVE-2013-0170" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0170.html"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1491.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1540" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1540.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1563" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1563.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2394" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2394.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2418" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2418.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2422.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2432.html"/>
        <reference source="CVE" ref_id="CVE-2013-2433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2433.html"/>
        <reference source="CVE" ref_id="CVE-2013-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2435.html"/>
        <reference source="CVE" ref_id="CVE-2013-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2440.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:48.191-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:04.357-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:15.988-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21111 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:26.566-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:35.295-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137176"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137693"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137603"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137719"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137800"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137825"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:136852"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.13.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137840"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90595"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91248"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90963"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90780"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90933"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91239"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.13.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91053"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21109" version="313" class="patch">
      <metadata>
        <title>RHSA-2013:0624: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0624-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0624.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2013-0409" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0409.html"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <reference source="CVE" ref_id="CVE-2013-1481" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1481.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:30.258-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:03.567-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:15.278-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21109 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:16.802-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:33.539-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137847"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137250"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137808"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137819"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137703"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137755"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137212"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.0-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137552"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90818"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90926"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90561"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90647"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90874"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90931"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.0-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21103" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0269: axis security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>axis</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0269-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0269.html"/>
        <reference source="CVE" ref_id="CVE-2012-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5784.html"/>
        <description>Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:42.117-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:03.280-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:15.013-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="axis is earlier than 0:1.2.1-7.3.el6_3" test_ref="oval:org.mitre.oval:tst:90479"/>
          <criterion comment="axis-manual is earlier than 0:1.2.1-7.3.el6_3" test_ref="oval:org.mitre.oval:tst:89784"/>
          <criterion comment="axis-javadoc is earlier than 0:1.2.1-7.3.el6_3" test_ref="oval:org.mitre.oval:tst:90442"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21102" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0628: 389-ds-base security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0628-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0628.html"/>
        <reference source="CESA" ref_id="CESA-2013:0628"/>
        <reference source="CVE" ref_id="CVE-2013-0312" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0312.html"/>
        <description>389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:16.114-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:03.186-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:14.679-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-12.el6_4" test_ref="oval:org.mitre.oval:tst:90722"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-12.el6_4" test_ref="oval:org.mitre.oval:tst:90862"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-12.el6_4" test_ref="oval:org.mitre.oval:tst:90665"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21099" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0748: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0748-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0748.html"/>
        <reference source="CESA" ref_id="CESA-2013:0748"/>
        <reference source="CVE" ref_id="CVE-2013-1416" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1416.html"/>
        <description>The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS-REQ request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:23.396-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:03.065-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:14.550-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:91220"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:91082"/>
          <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:91280"/>
          <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:90283"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:90707"/>
          <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:91104"/>
          <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.2" test_ref="oval:org.mitre.oval:tst:91033"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21098" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0350: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0350-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0350.html"/>
        <reference source="CESA" ref_id="CESA-2012:0350"/>
        <reference source="CVE" ref_id="CVE-2011-4077" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4077.html"/>
        <reference source="CVE" ref_id="CVE-2011-4081" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4081.html"/>
        <reference source="CVE" ref_id="CVE-2011-4132" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4132.html"/>
        <reference source="CVE" ref_id="CVE-2011-4347" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4347.html"/>
        <reference source="CVE" ref_id="CVE-2011-4594" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4594.html"/>
        <reference source="CVE" ref_id="CVE-2011-4611" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4611.html"/>
        <reference source="CVE" ref_id="CVE-2011-4622" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4622.html"/>
        <reference source="CVE" ref_id="CVE-2012-0038" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0038.html"/>
        <reference source="CVE" ref_id="CVE-2012-0045" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0045.html"/>
        <reference source="CVE" ref_id="CVE-2012-0207" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0207.html"/>
        <description>The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:46.739-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:30.522-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:48.192-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:93050"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:92949"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:92908"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:92892"/>
          <criterion comment="perf is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:92714"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:92996"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:92472"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:92739"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:93048"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:92617"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:93072"/>
          <criterion comment="kernel is earlier than 0:2.6.32-220.7.1.el6" test_ref="oval:org.mitre.oval:tst:92930"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21092" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:1475: postgresql and postgresql84 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>postgresql84</product>
          <product>postgresql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1475-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1475.html"/>
        <reference source="CESA" ref_id="CESA-2013:1475"/>
        <reference source="CVE" ref_id="CVE-2013-0255" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0255.html"/>
        <reference source="CVE" ref_id="CVE-2013-1000" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1000.html"/>
        <description>WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:07.659-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:02.541-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:14.019-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql-devel is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91210"/>
            <criterion comment="postgresql is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91903"/>
            <criterion comment="postgresql-plperl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91694"/>
            <criterion comment="postgresql-server is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:90932"/>
            <criterion comment="postgresql-plpython is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91788"/>
            <criterion comment="postgresql-pltcl is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91252"/>
            <criterion comment="postgresql-contrib is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91881"/>
            <criterion comment="postgresql-libs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91810"/>
            <criterion comment="postgresql-docs is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91746"/>
            <criterion comment="postgresql-test is earlier than 0:8.4.18-1.el6_4" test_ref="oval:org.mitre.oval:tst:91861"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="postgresql84-pltcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91711"/>
            <criterion comment="postgresql84-libs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91494"/>
            <criterion comment="postgresql84-docs is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91685"/>
            <criterion comment="postgresql84-python is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91420"/>
            <criterion comment="postgresql84-test is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91447"/>
            <criterion comment="postgresql84-server is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91748"/>
            <criterion comment="postgresql84-tcl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91925"/>
            <criterion comment="postgresql84-plperl is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91362"/>
            <criterion comment="postgresql84-contrib is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91655"/>
            <criterion comment="postgresql84-plpython is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91623"/>
            <criterion comment="postgresql84-devel is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91744"/>
            <criterion comment="postgresql84 is earlier than 0:8.4.18-1.el5_10" test_ref="oval:org.mitre.oval:tst:91528"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21088" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0427: libtasn1 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libtasn1</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0427-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0427.html"/>
        <reference source="CESA" ref_id="CESA-2012:0427"/>
        <reference source="CVE" ref_id="CVE-2012-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1569.html"/>
        <description>The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified other impact via a crafted ASN.1 structure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:29.047-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:29.945-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:47.460-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libtasn1-tools is earlier than 0:2.3-3.el6_2.1" test_ref="oval:org.mitre.oval:tst:93143"/>
          <criterion comment="libtasn1 is earlier than 0:2.3-3.el6_2.1" test_ref="oval:org.mitre.oval:tst:93332"/>
          <criterion comment="libtasn1-devel is earlier than 0:2.3-3.el6_2.1" test_ref="oval:org.mitre.oval:tst:92919"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21087" version="133" class="patch">
      <metadata>
        <title>RHSA-2012:0387: firefox security and bug fix update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0387-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0387.html"/>
        <reference source="CESA" ref_id="CESA-2012:0387"/>
        <reference source="CVE" ref_id="CVE-2012-0451" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0451.html"/>
        <reference source="CVE" ref_id="CVE-2012-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0455.html"/>
        <reference source="CVE" ref_id="CVE-2012-0456" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0456.html"/>
        <reference source="CVE" ref_id="CVE-2012-0457" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0457.html"/>
        <reference source="CVE" ref_id="CVE-2012-0458" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0458.html"/>
        <reference source="CVE" ref_id="CVE-2012-0459" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0459.html"/>
        <reference source="CVE" ref_id="CVE-2012-0460" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0460.html"/>
        <reference source="CVE" ref_id="CVE-2012-0461" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0461.html"/>
        <reference source="CVE" ref_id="CVE-2012-0462" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0462.html"/>
        <reference source="CVE" ref_id="CVE-2012-0464" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0464.html"/>
        <description>Use-after-free vulnerability in the browser engine in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to execute arbitrary code via vectors involving an empty argument to the array.join function in conjunction with the triggering of garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:26.579-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:29.487-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:47.024-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:93064"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:92951"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.3-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94850"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.3-1.el5_8" test_ref="oval:org.mitre.oval:tst:93068"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:92147"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:92353"/>
            <criterion comment="firefox is earlier than 0:10.0.3-1.el6_2" test_ref="oval:org.mitre.oval:tst:93085"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94340"/>
            <criterion comment="xulrunner is earlier than 0:10.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94760"/>
            <criterion comment="firefox is earlier than 0:10.0.3-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94988"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21086" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0550: bind security and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0550-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0550.html"/>
        <reference source="CESA" ref_id="CESA-2013:0550"/>
        <reference source="CVE" ref_id="CVE-2012-5689" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5689.html"/>
        <description>ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:43.915-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:02.258-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:13.789-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:90706"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:90330"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:90440"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:89834"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:90709"/>
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.17.rc1.el6.3" test_ref="oval:org.mitre.oval:tst:90666"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21085" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0589: git security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>git</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0589-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0589.html"/>
        <reference source="CESA" ref_id="CESA-2013:0589"/>
        <reference source="CVE" ref_id="CVE-2013-0308" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0308.html"/>
        <description>The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:54.293-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:02.136-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:13.685-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="git-cvs is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:90670"/>
          <criterion comment="git-email is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:90521"/>
          <criterion comment="gitk is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:89814"/>
          <criterion comment="emacs-git-el is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:90652"/>
          <criterion comment="git-daemon is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:89910"/>
          <criterion comment="git-svn is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:90643"/>
          <criterion comment="git-all is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:90752"/>
          <criterion comment="git-gui is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:90578"/>
          <criterion comment="emacs-git is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:90777"/>
          <criterion comment="gitweb is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:90472"/>
          <criterion comment="git is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:90633"/>
          <criterion comment="perl-Git is earlier than 0:1.7.1-3.el6_4.1" test_ref="oval:org.mitre.oval:tst:90663"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21083" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1202: libvirt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1202-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1202.html"/>
        <reference source="CESA" ref_id="CESA-2012:1202"/>
        <reference source="CVE" ref_id="CVE-2012-3445" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3445.html"/>
        <description>The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set to zero, which triggers an out-of-bounds read or a free of an invalid pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:59.390-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:29.385-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:46.863-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.el6_3.4" test_ref="oval:org.mitre.oval:tst:94177"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.el6_3.4" test_ref="oval:org.mitre.oval:tst:94318"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.el6_3.4" test_ref="oval:org.mitre.oval:tst:94109"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.9.10-21.el6_3.4" test_ref="oval:org.mitre.oval:tst:94438"/>
          <criterion comment="libvirt is earlier than 0:0.9.10-21.el6_3.4" test_ref="oval:org.mitre.oval:tst:93474"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21082" version="7" class="patch">
      <metadata>
        <title>RHSA-2013:1868: xorg-x11-server security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-server</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1868-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1868.html"/>
        <reference source="CESA" ref_id="CESA-2013:1868"/>
        <reference source="CVE" ref_id="CVE-2013-6424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6424.html"/>
        <description>Integer underflow in the xTrapezoidValid macro in render/picture.h in X.Org allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:39.355-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.809-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:13.427-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21082 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.620-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:23.064-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:92119"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:91723"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:91970"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:92093"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:92104"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:91938"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:91734"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.el5_10.2" test_ref="oval:org.mitre.oval:tst:91224"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92235"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:91754"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92138"/>
            <criterion comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92040"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:91302"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92140"/>
            <criterion comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92271"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.101.0.1.el5.centos.2" test_ref="oval:org.mitre.oval:tst:92007"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92103"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:91238"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:91728"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:91968"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92165"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92211"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92011"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92142"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.1.el6_5" test_ref="oval:org.mitre.oval:tst:92183"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:92206"/>
            <criterion comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:92000"/>
            <criterion comment="xorg-x11-server is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:92298"/>
            <criterion comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:91875"/>
            <criterion comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:92089"/>
            <criterion comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:91984"/>
            <criterion comment="xorg-x11-server-common is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:92074"/>
            <criterion comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:91916"/>
            <criterion comment="xorg-x11-server-source is earlier than 0:1.13.0-23.1.el6.centos" test_ref="oval:org.mitre.oval:tst:91846"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21081" version="35" class="patch">
      <metadata>
        <title>RHSA-2013:1818: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1818-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1818.html"/>
        <reference source="CVE" ref_id="CVE-2013-5331" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5331.html"/>
        <reference source="CVE" ref_id="CVE-2013-5332" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5332.html"/>
        <description>Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK &amp; Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:12.191-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.567-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:13.133-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21081 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:39.906-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:22.856-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21081 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:13.490-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:33.149-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.332-1.el5" test_ref="oval:org.mitre.oval:tst:137609"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.332-1.el6" test_ref="oval:org.mitre.oval:tst:91627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21079" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0587: openssl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0587-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0587.html"/>
        <reference source="CESA" ref_id="CESA-2013:0587"/>
        <reference source="CVE" ref_id="CVE-2012-4929" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4929.html"/>
        <reference source="CVE" ref_id="CVE-2013-0166" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0166.html"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <description>The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:00.653-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.401-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:12.983-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:90640"/>
            <criterion comment="openssl-static is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:90437"/>
            <criterion comment="openssl-perl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:90553"/>
            <criterion comment="openssl is earlier than 0:1.0.0-27.el6_4.2" test_ref="oval:org.mitre.oval:tst:90590"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="openssl-devel is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:90602"/>
            <criterion comment="openssl-perl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:90398"/>
            <criterion comment="openssl is earlier than 0:0.9.8e-26.el5_9.1" test_ref="oval:org.mitre.oval:tst:90527"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21078" version="61" class="patch">
      <metadata>
        <title>RHSA-2013:0730: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0730-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0730.html"/>
        <reference source="CVE" ref_id="CVE-2013-1378" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1378.html"/>
        <reference source="CVE" ref_id="CVE-2013-1379" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1379.html"/>
        <reference source="CVE" ref_id="CVE-2013-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1380.html"/>
        <reference source="CVE" ref_id="CVE-2013-2555" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2555.html"/>
        <description>Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK &amp; Compiler before 3.7.0.1530 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:34.877-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.247-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:12.774-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21078 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:17.123-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:32.684-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.280-1.el5" test_ref="oval:org.mitre.oval:tst:137412"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.280-2.el6" test_ref="oval:org.mitre.oval:tst:90863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21077" version="467" class="patch">
      <metadata>
        <title>RHSA-2013:0625: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0625-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0625.html"/>
        <reference source="CVE" ref_id="CVE-2012-1541" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1541.html"/>
        <reference source="CVE" ref_id="CVE-2012-3213" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3213.html"/>
        <reference source="CVE" ref_id="CVE-2012-3342" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3342.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2013-0351" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0351.html"/>
        <reference source="CVE" ref_id="CVE-2013-0409" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0409.html"/>
        <reference source="CVE" ref_id="CVE-2013-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0419.html"/>
        <reference source="CVE" ref_id="CVE-2013-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0423.html"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0435.html"/>
        <reference source="CVE" ref_id="CVE-2013-0438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0438.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0441.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0446.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1473.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <reference source="CVE" ref_id="CVE-2013-1481" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1481.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <reference source="CVE" ref_id="CVE-2013-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1487.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:56.595-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:01.045-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:12.494-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21077 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:17.697-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:29.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137838"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137346"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137593"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137842"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137639"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137758"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137583"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.13.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137672"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90948"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90391"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90795"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90772"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90660"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90411"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.13.0-1jpp.3.el6_4" test_ref="oval:org.mitre.oval:tst:90935"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21076" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:0517: util-linux-ng security, bug fix and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>util-linux-ng</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0517-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0517.html"/>
        <reference source="CESA" ref_id="CESA-2013:0517"/>
        <reference source="CVE" ref_id="CVE-2013-0157" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0157.html"/>
        <description>(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-fstype command-line option or (2) attempting to mount a non-existent device, which generates different error messages depending on whether the directory exists.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:54.857-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:00.906-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:12.364-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="util-linux-ng is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:90461"/>
          <criterion comment="uuidd is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:90043"/>
          <criterion comment="libuuid is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:89915"/>
          <criterion comment="libuuid-devel is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:89789"/>
          <criterion comment="libblkid is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:90368"/>
          <criterion comment="libblkid-devel is earlier than 0:2.17.2-12.9.el6" test_ref="oval:org.mitre.oval:tst:90448"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21075" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0623: tomcat6 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0623-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0623.html"/>
        <reference source="CESA" ref_id="CESA-2013:0623"/>
        <reference source="CVE" ref_id="CVE-2012-3546" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3546.html"/>
        <reference source="CVE" ref_id="CVE-2012-4534" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4534.html"/>
        <reference source="CVE" ref_id="CVE-2012-5885" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5885.html"/>
        <reference source="CVE" ref_id="CVE-2012-5886" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5886.html"/>
        <reference source="CVE" ref_id="CVE-2012-5887" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5887.html"/>
        <description>The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly check for stale nonce values in conjunction with enforcement of proper credentials, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:08.281-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:00.673-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:12.128-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:90651"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:90699"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:90944"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:90747"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:90565"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:90985"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:90837"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:90941"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-52.el6_4" test_ref="oval:org.mitre.oval:tst:90000"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21074" version="311" class="patch">
      <metadata>
        <title>RHSA-2013:0751: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0751-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0751.html"/>
        <reference source="CESA" ref_id="CESA-2013:0751"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1488" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1488.html"/>
        <reference source="CVE" ref_id="CVE-2013-1518" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1518.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1558.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2415.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2421.html"/>
        <reference source="CVE" ref_id="CVE-2013-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2422.html"/>
        <reference source="CVE" ref_id="CVE-2013-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2423.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2426.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2431" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2431.html"/>
        <reference source="CVE" ref_id="CVE-2013-2436" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2436.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-1488 and CVE-2013-2426.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect "type checks" and "method handle binding" involving Wrapper.convert.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:26.481-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:01:00.108-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:11.281-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.19-2.3.9.1.el6_4" test_ref="oval:org.mitre.oval:tst:91266"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.19-2.3.9.1.el6_4" test_ref="oval:org.mitre.oval:tst:91251"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.19-2.3.9.1.el6_4" test_ref="oval:org.mitre.oval:tst:90721"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.19-2.3.9.1.el6_4" test_ref="oval:org.mitre.oval:tst:91195"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.19-2.3.9.1.el6_4" test_ref="oval:org.mitre.oval:tst:90395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21072" version="29" class="patch">
      <metadata>
        <title>RHSA-2011:0616: pidgin security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0616-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0616.html"/>
        <reference source="CVE" ref_id="CVE-2011-1091" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1091.html"/>
        <reference source="CVE" ref_id="CVE-2011-4922" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4922.html"/>
        <description>cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:30.280-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:29.207-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:46.581-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pidgin-docs is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:98001"/>
          <criterion comment="pidgin-perl is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:97777"/>
          <criterion comment="libpurple-tcl is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:97913"/>
          <criterion comment="libpurple is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:97995"/>
          <criterion comment="finch-devel is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:97756"/>
          <criterion comment="libpurple-perl is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:97639"/>
          <criterion comment="finch is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:97852"/>
          <criterion comment="libpurple-devel is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:97780"/>
          <criterion comment="pidgin-devel is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:98029"/>
          <criterion comment="pidgin is earlier than 0:2.7.9-3.el6" test_ref="oval:org.mitre.oval:tst:97076"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21071" version="211" class="patch">
      <metadata>
        <title>RHSA-2012:1482: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1482-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1482.html"/>
        <reference source="CESA" ref_id="CESA-2012:1482"/>
        <reference source="CVE" ref_id="CVE-2012-4201" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4201.html"/>
        <reference source="CVE" ref_id="CVE-2012-4202" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4202.html"/>
        <reference source="CVE" ref_id="CVE-2012-4207" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4207.html"/>
        <reference source="CVE" ref_id="CVE-2012-4209" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4209.html"/>
        <reference source="CVE" ref_id="CVE-2012-4210" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4210.html"/>
        <reference source="CVE" ref_id="CVE-2012-4214" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4214.html"/>
        <reference source="CVE" ref_id="CVE-2012-4215" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4215.html"/>
        <reference source="CVE" ref_id="CVE-2012-4216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4216.html"/>
        <reference source="CVE" ref_id="CVE-2012-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5829.html"/>
        <reference source="CVE" ref_id="CVE-2012-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5830.html"/>
        <reference source="CVE" ref_id="CVE-2012-5833" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5833.html"/>
        <reference source="CVE" ref_id="CVE-2012-5835" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5835.html"/>
        <reference source="CVE" ref_id="CVE-2012-5839" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5839.html"/>
        <reference source="CVE" ref_id="CVE-2012-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5840.html"/>
        <reference source="CVE" ref_id="CVE-2012-5841" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5841.html"/>
        <reference source="CVE" ref_id="CVE-2012-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5842.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:41.005-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:28.686-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:46.000-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:94503"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:94930"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.11-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94533"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.11-1.el5_8" test_ref="oval:org.mitre.oval:tst:94399"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:94944"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:94847"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el6_3" test_ref="oval:org.mitre.oval:tst:94355"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.11-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94784"/>
            <criterion comment="xulrunner is earlier than 0:10.0.11-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94666"/>
            <criterion comment="firefox is earlier than 0:10.0.11-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94518"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21068" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:1436: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1436-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1436.html"/>
        <reference source="CESA" ref_id="CESA-2013:1436"/>
        <reference source="CVE" ref_id="CVE-2013-4162" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4162.html"/>
        <reference source="CVE" ref_id="CVE-2013-4299" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4299.html"/>
        <description>Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:08.858-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:59.676-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:10.838-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91700"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91874"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91133"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91288"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91815"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91857"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91645"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91562"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91725"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91825"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91330"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.23.2.el6" test_ref="oval:org.mitre.oval:tst:91793"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21067" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0815: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0815-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0815.html"/>
        <reference source="CESA" ref_id="CESA-2013:0815"/>
        <reference source="CVE" ref_id="CVE-2012-3499" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3499.html"/>
        <reference source="CVE" ref_id="CVE-2012-4558" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4558.html"/>
        <reference source="CVE" ref_id="CVE-2013-1862" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1862.html"/>
        <description>mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:24.306-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:59.298-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:10.580-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:91174"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:91249"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:90739"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:91193"/>
            <criterion comment="httpd is earlier than 0:2.2.15-28.el6_4" test_ref="oval:org.mitre.oval:tst:91064"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-28.el6.centos" test_ref="oval:org.mitre.oval:tst:91852"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-28.el6.centos" test_ref="oval:org.mitre.oval:tst:91823"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-28.el6.centos" test_ref="oval:org.mitre.oval:tst:92124"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.15-28.el6.centos" test_ref="oval:org.mitre.oval:tst:91946"/>
            <criterion comment="httpd is earlier than 0:2.2.15-28.el6.centos" test_ref="oval:org.mitre.oval:tst:91985"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:90743"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:91260"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:90956"/>
            <criterion comment="httpd is earlier than 0:2.2.3-78.el5_9" test_ref="oval:org.mitre.oval:tst:90812"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.3-78.el5.centos" test_ref="oval:org.mitre.oval:tst:92008"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-78.el5.centos" test_ref="oval:org.mitre.oval:tst:92248"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.3-78.el5.centos" test_ref="oval:org.mitre.oval:tst:91618"/>
            <criterion comment="httpd is earlier than 0:2.2.3-78.el5.centos" test_ref="oval:org.mitre.oval:tst:91837"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21066" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0512: httpd security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0512-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0512.html"/>
        <reference source="CESA" ref_id="CESA-2013:0512"/>
        <reference source="CVE" ref_id="CVE-2008-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0455.html"/>
        <reference source="CVE" ref_id="CVE-2012-2687" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2687.html"/>
        <reference source="CVE" ref_id="CVE-2012-4557" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4557.html"/>
        <description>The mod_proxy_ajp module in the Apache HTTP Server 2.2.12 through 2.2.21 places a worker node into an error state upon detection of a long request-processing time, which allows remote attackers to cause a denial of service (worker consumption) via an expensive request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:03.184-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:59.118-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:10.361-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-26.el6" test_ref="oval:org.mitre.oval:tst:90533"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-26.el6" test_ref="oval:org.mitre.oval:tst:90384"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-26.el6" test_ref="oval:org.mitre.oval:tst:90558"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-26.el6" test_ref="oval:org.mitre.oval:tst:90210"/>
            <criterion comment="httpd is earlier than 0:2.2.15-26.el6" test_ref="oval:org.mitre.oval:tst:90534"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-26.el6.centos" test_ref="oval:org.mitre.oval:tst:92152"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-26.el6.centos" test_ref="oval:org.mitre.oval:tst:91922"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-26.el6.centos" test_ref="oval:org.mitre.oval:tst:91442"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-26.el6.centos" test_ref="oval:org.mitre.oval:tst:91284"/>
            <criterion comment="httpd is earlier than 0:2.2.15-26.el6.centos" test_ref="oval:org.mitre.oval:tst:92214"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21060" version="7" class="patch">
      <metadata>
        <title>RHSA-2013:1869: pixman security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>pixman</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1869-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1869.html"/>
        <reference source="CESA" ref_id="CESA-2013:1869"/>
        <reference source="CVE" ref_id="CVE-2013-6425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6425.html"/>
        <description>Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:15.100-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:58.780-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:10.008-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21060 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:40.360-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:21.111-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="pixman-devel is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:92053"/>
            <criterion comment="pixman is earlier than 0:0.22.0-2.2.el5_10" test_ref="oval:org.mitre.oval:tst:92234"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="pixman-devel is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:92222"/>
            <criterion comment="pixman is earlier than 0:0.26.2-5.1.el6_5" test_ref="oval:org.mitre.oval:tst:92046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21059" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0590: nss-pam-ldapd security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>nss-pam-ldapd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0590-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0590.html"/>
        <reference source="CESA" ref_id="CESA-2013:0590"/>
        <reference source="CVE" ref_id="CVE-2013-0288" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0288.html"/>
        <description>nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:58.934-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:58.614-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:09.900-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="nss-pam-ldapd is earlier than 0:0.7.5-18.1.el6_4" test_ref="oval:org.mitre.oval:tst:90872"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21052" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0568: dbus-glib security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>dbus-glib</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0568-03" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0568.html"/>
        <reference source="CESA" ref_id="CESA-2013:0568"/>
        <reference source="CVE" ref_id="CVE-2013-0292" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0292.html"/>
        <description>The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:00.813-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:58.186-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:09.699-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-glib is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:90708"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.86-6.el6_4" test_ref="oval:org.mitre.oval:tst:90455"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-glib is earlier than 0:0.86-6.el6" test_ref="oval:org.mitre.oval:tst:91997"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.86-6.el6" test_ref="oval:org.mitre.oval:tst:91937"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="dbus-glib is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:90436"/>
            <criterion comment="dbus-glib-devel is earlier than 0:0.73-11.el5_9" test_ref="oval:org.mitre.oval:tst:90314"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21050" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0567: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0567-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0567.html"/>
        <reference source="CESA" ref_id="CESA-2013:0567"/>
        <reference source="CVE" ref_id="CVE-2013-0871" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0871.html"/>
        <description>Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:13.803-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:58.043-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:09.556-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:90639"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:90588"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:90608"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:90729"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:89785"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:90546"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:90734"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:90536"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:90755"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:90383"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:90767"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.0.1.el6" test_ref="oval:org.mitre.oval:tst:89767"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21046" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0270: jakarta-commons-httpclient security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>jakarta-commons-httpclient</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0270-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0270.html"/>
        <reference source="CESA" ref_id="CESA-2013:0270"/>
        <reference source="CVE" ref_id="CVE-2012-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5783.html"/>
        <description>Apache Commons HttpClient 3.x, as used in Amazon Flexible Payments Service (FPS) merchant Java SDK and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:04.852-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:57.867-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:09.338-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:90251"/>
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:89947"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:90456"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-0.7.el6_3" test_ref="oval:org.mitre.oval:tst:90471"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:90319"/>
            <criterion comment="jakarta-commons-httpclient is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:90312"/>
            <criterion comment="jakarta-commons-httpclient-demo is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:90497"/>
            <criterion comment="jakarta-commons-httpclient-manual is earlier than 1:3.0-7jpp.2" test_ref="oval:org.mitre.oval:tst:90286"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21045" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1132: icedtea-web security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1132.html"/>
        <reference source="CESA" ref_id="CESA-2012:1132"/>
        <reference source="CVE" ref_id="CVE-2012-3422" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3422.html"/>
        <reference source="CVE" ref_id="CVE-2012-3423" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3423.html"/>
        <description>The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:32.086-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:27.811-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:44.950-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.2.1-1.el6_3" test_ref="oval:org.mitre.oval:tst:93863"/>
          <criterion comment="icedtea-web is earlier than 0:1.2.1-1.el6_3" test_ref="oval:org.mitre.oval:tst:94062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21044" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0526: automake security update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>automake</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0526-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0526.html"/>
        <reference source="CESA" ref_id="CESA-2013:0526"/>
        <reference source="CVE" ref_id="CVE-2012-3386" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3386.html"/>
        <description>The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:03.828-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:57.762-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:09.190-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="automake is earlier than 0:1.11.1-4.el6" test_ref="oval:org.mitre.oval:tst:90644"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21042" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0515: openchange security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>evolution-mapi</product>
          <product>openchange</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0515-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0515.html"/>
        <reference source="CESA" ref_id="CESA-2013:0515"/>
        <reference source="CVE" ref_id="CVE-2012-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1182.html"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:46.430-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:57.599-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:09.072-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openchange is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:90636"/>
          <criterion comment="openchange-devel is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:90495"/>
          <criterion comment="openchange-client is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:90025"/>
          <criterion comment="openchange-devel-docs is earlier than 0:1.0-4.el6" test_ref="oval:org.mitre.oval:tst:90365"/>
          <criterion comment="evolution-mapi is earlier than 0:0.28.3-12.el6" test_ref="oval:org.mitre.oval:tst:90654"/>
          <criterion comment="evolution-mapi-devel is earlier than 0:0.28.3-12.el6" test_ref="oval:org.mitre.oval:tst:90620"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21040" version="579" class="patch">
      <metadata>
        <title>RHSA-2013:0626: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0626-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0626.html"/>
        <reference source="CVE" ref_id="CVE-2012-1541" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1541.html"/>
        <reference source="CVE" ref_id="CVE-2012-3174" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3174.html"/>
        <reference source="CVE" ref_id="CVE-2012-3213" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3213.html"/>
        <reference source="CVE" ref_id="CVE-2012-3342" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3342.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2013-0351" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0351.html"/>
        <reference source="CVE" ref_id="CVE-2013-0409" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0409.html"/>
        <reference source="CVE" ref_id="CVE-2013-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0419.html"/>
        <reference source="CVE" ref_id="CVE-2013-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0422.html"/>
        <reference source="CVE" ref_id="CVE-2013-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0423.html"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0431" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0431.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0435.html"/>
        <reference source="CVE" ref_id="CVE-2013-0437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0437.html"/>
        <reference source="CVE" ref_id="CVE-2013-0438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0438.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0441.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0444.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0446.html"/>
        <reference source="CVE" ref_id="CVE-2013-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0449.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1473.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <reference source="CVE" ref_id="CVE-2013-1484" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1484.html"/>
        <reference source="CVE" ref_id="CVE-2013-1485" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1485.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <reference source="CVE" ref_id="CVE-2013-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1487.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:58.469-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:56.474-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:07.303-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21040 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:33.045-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:26.843-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137621"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137785"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137762"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137817"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137767"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.4.0-1jpp.2.el5_9" test_ref="oval:org.mitre.oval:tst:137520"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90834"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90994"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90918"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90840"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90745"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.4.0-1jpp.2.el6_4" test_ref="oval:org.mitre.oval:tst:90989"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21038" version="143" class="patch">
      <metadata>
        <title>RHSA-2013:0821: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0821-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0821.html"/>
        <reference source="CESA" ref_id="CESA-2013:0821"/>
        <reference source="CVE" ref_id="CVE-2013-0801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0801.html"/>
        <reference source="CVE" ref_id="CVE-2013-1670" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1670.html"/>
        <reference source="CVE" ref_id="CVE-2013-1674" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1674.html"/>
        <reference source="CVE" ref_id="CVE-2013-1675" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1675.html"/>
        <reference source="CVE" ref_id="CVE-2013-1676" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1676.html"/>
        <reference source="CVE" ref_id="CVE-2013-1677" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1677.html"/>
        <reference source="CVE" ref_id="CVE-2013-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1678.html"/>
        <reference source="CVE" ref_id="CVE-2013-1679" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1679.html"/>
        <reference source="CVE" ref_id="CVE-2013-1680" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1680.html"/>
        <reference source="CVE" ref_id="CVE-2013-1681" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1681.html"/>
        <description>Use-after-free vulnerability in the nsContentUtils::RemoveScriptBlocker function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:24.362-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:55.938-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:06.782-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.6-2.el6_4" test_ref="oval:org.mitre.oval:tst:91173"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.6-2.el6.centos" test_ref="oval:org.mitre.oval:tst:91935"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.6-1.el5_9" test_ref="oval:org.mitre.oval:tst:90899"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.6-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91580"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21037" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1409: xinetd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1409-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1409.html"/>
        <reference source="CESA" ref_id="CESA-2013:1409"/>
        <reference source="CVE" ref_id="CVE-2013-4342" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4342.html"/>
        <description>xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:54.134-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:55.831-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:06.638-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criterion comment="xinetd is earlier than 2:2.3.14-39.el6_4" test_ref="oval:org.mitre.oval:tst:91670"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="xinetd is earlier than 2:2.3.14-20.el5_10" test_ref="oval:org.mitre.oval:tst:91703"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21034" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0896: qemu-kvm security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0896-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0896.html"/>
        <reference source="CESA" ref_id="CESA-2013:0896"/>
        <reference source="CVE" ref_id="CVE-2013-2007" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2007.html"/>
        <description>The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows local users to read and write to these files.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:19.773-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:55.562-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:06.271-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="qemu-guest-agent-win32 is earlier than 2:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:91261"/>
            <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:91338"/>
            <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:91309"/>
            <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:90951"/>
            <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.355.el6_4.5" test_ref="oval:org.mitre.oval:tst:91152"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="qemu-guest-agent-win32 is earlier than 2:0.12.1.2-2.355.0.1.el6.centos.5" test_ref="oval:org.mitre.oval:tst:92239"/>
            <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.355.0.1.el6.centos.5" test_ref="oval:org.mitre.oval:tst:91410"/>
            <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.355.0.1.el6.centos.5" test_ref="oval:org.mitre.oval:tst:92249"/>
            <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.355.0.1.el6.centos.5" test_ref="oval:org.mitre.oval:tst:92227"/>
            <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.355.0.1.el6.centos.5" test_ref="oval:org.mitre.oval:tst:92161"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21027" version="33" class="patch">
      <metadata>
        <title>RHSA-2013:0551: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0551-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0551.html"/>
        <reference source="CVE" ref_id="CVE-2013-0640" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0640.html"/>
        <reference source="CVE" ref_id="CVE-2013-0641" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0641.html"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allows remote attackers to execute arbitrary code via a crafted PDF document, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:23.145-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:55.258-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:05.963-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21027 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:30.328-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:26.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.4-1.el5_9" test_ref="oval:org.mitre.oval:tst:137432"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.4-1.el5_9" test_ref="oval:org.mitre.oval:tst:137180"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.4-1.el6" test_ref="oval:org.mitre.oval:tst:90664"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.4-1.el6" test_ref="oval:org.mitre.oval:tst:90649"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21011" version="304" class="patch">
      <metadata>
        <title>RHSA-2012:1466: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1466-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1466.html"/>
        <reference source="CVE" ref_id="CVE-2012-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0547.html"/>
        <reference source="CVE" ref_id="CVE-2012-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1531.html"/>
        <reference source="CVE" ref_id="CVE-2012-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1532.html"/>
        <reference source="CVE" ref_id="CVE-2012-1533" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1533.html"/>
        <reference source="CVE" ref_id="CVE-2012-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1682.html"/>
        <reference source="CVE" ref_id="CVE-2012-3143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3143.html"/>
        <reference source="CVE" ref_id="CVE-2012-3159" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3159.html"/>
        <reference source="CVE" ref_id="CVE-2012-3216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3216.html"/>
        <reference source="CVE" ref_id="CVE-2012-4820" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4820.html"/>
        <reference source="CVE" ref_id="CVE-2012-4822" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4822.html"/>
        <reference source="CVE" ref_id="CVE-2012-4823" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4823.html"/>
        <reference source="CVE" ref_id="CVE-2012-5068" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5068.html"/>
        <reference source="CVE" ref_id="CVE-2012-5069" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5069.html"/>
        <reference source="CVE" ref_id="CVE-2012-5071" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5071.html"/>
        <reference source="CVE" ref_id="CVE-2012-5072" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5072.html"/>
        <reference source="CVE" ref_id="CVE-2012-5073" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5073.html"/>
        <reference source="CVE" ref_id="CVE-2012-5075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5075.html"/>
        <reference source="CVE" ref_id="CVE-2012-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5079.html"/>
        <reference source="CVE" ref_id="CVE-2012-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5081.html"/>
        <reference source="CVE" ref_id="CVE-2012-5083" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5083.html"/>
        <reference source="CVE" ref_id="CVE-2012-5084" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5084.html"/>
        <reference source="CVE" ref_id="CVE-2012-5089" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5089.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "IIOP type reuse management" in ObjectStreamClass.java.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:40.068-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:26.650-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:43.165-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21011 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:25.332-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:24.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137931"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137756"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137957"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137093"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137900"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137918"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137791"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.12.0-1jpp.1.el5_8" test_ref="oval:org.mitre.oval:tst:137982"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94420"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94154"/>
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94688"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94868"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94715"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94806"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.12.0-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21010" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1779: mod_nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>mod_nss</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1779-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1779.html"/>
        <reference source="CESA" ref_id="CESA-2013:1779"/>
        <reference source="CVE" ref_id="CVE-2013-4566" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4566.html"/>
        <description>mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:20.086-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:54.295-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:05.203-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="mod_nss is earlier than 0:1.0.8-8.el5_10" test_ref="oval:org.mitre.oval:tst:91316"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="mod_nss is earlier than 0:1.0.8-19.el6_5" test_ref="oval:org.mitre.oval:tst:91691"/>
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21009" version="6" class="patch">
      <metadata>
        <title>RHSA-2013:0149: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0149-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0149.html"/>
        <reference source="CVE" ref_id="CVE-2013-0630" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0630.html"/>
        <description>Buffer overflow in Adobe Flash Player before 10.3.183.50 and 11.x before 11.5.502.146 on Windows and Mac OS X, before 10.3.183.50 and 11.x before 11.2.202.261 on Linux, before 11.1.111.31 on Android 2.x and 3.x, and before 11.1.115.36 on Android 4.x; Adobe AIR before 3.5.0.1060; and Adobe AIR SDK before 3.5.0.1060 allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:01.231-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:54.205-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:05.106-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21009 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:05.301-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:23.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.261-1.el5" test_ref="oval:org.mitre.oval:tst:137548"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.261-1.el6" test_ref="oval:org.mitre.oval:tst:90331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21008" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:1142: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1142-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1142.html"/>
        <reference source="CESA" ref_id="CESA-2013:1142"/>
        <reference source="CVE" ref_id="CVE-2013-1701" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1701.html"/>
        <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed content. Malicious
content could cause Thunderbird to crash or, potentially, execute arbitrary
code with the privileges of the user running Thunderbird. (CVE-2013-1701)

A flaw was found in the way Thunderbird generated Certificate Request
Message Format (CRMF) requests. An attacker could use this flaw to perform
cross-site scripting (XSS) attacks or execute arbitrary code with the
privileges of the user running Thunderbird. (CVE-2013-1710)

A flaw was found in the way Thunderbird handled the interaction between
frames and browser history. An attacker could use this flaw to trick
Thunderbird into treating malicious content as if it came from the browser
history, allowing for XSS attacks. (CVE-2013-1709)

It was found that the same-origin policy could be bypassed due to the way
Uniform Resource Identifiers (URI) were checked in JavaScript. An attacker
could use this flaw to perform XSS attacks, or install malicious add-ons
from third-party pages. (CVE-2013-1713)

It was found that web workers could bypass the same-origin policy. An
attacker could use this flaw to perform XSS attacks. (CVE-2013-1714)

It was found that, in certain circumstances, Thunderbird incorrectly
handled Java applets. If a user launched an untrusted Java applet via
Thunderbird, the applet could use this flaw to obtain read-only access to
files on the user's local system. (CVE-2013-1717)

Red Hat would like to thank the Mozilla project for reporting these issues.
Upstream acknowledges Jeff Gilbert, Henrik Skupin, moz_bug_r_a4, Cody
Crews, Federico Lanusse, and Georgi Guninski as the original reporters of
these issues.

Note: All of the above issues cannot be exploited by a specially-crafted
HTML mail message as JavaScript is disabled by default for mail messages.
They could be exploited another way in Thunderbird, for example, when
viewing the full remote content of an RSS feed.

All Thunderbird users should upgrade to this updated package, which
contains Thunderbird version 17.0.8 ESR, which corrects these issues. After
installing the update, Thunderbird must be restarted for the changes to
take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:21.437-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:54.093-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:04.962-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:21008 - modified Vulnerability definition of CVE-2013-1701 for CentOS" date="2014-05-30T10:40:00.295-04:00">
              <contributor organization="Hewlett-Packard">Prashant Kumar</contributor>
            </modified>
            <status_change date="2014-05-30T10:42:17.655-04:00">INTERIM</status_change>
            <status_change date="2014-06-16T04:00:08.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el6_4" test_ref="oval:org.mitre.oval:tst:91629"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el6.centos" test_ref="oval:org.mitre.oval:tst:92027"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el5_9" test_ref="oval:org.mitre.oval:tst:91431"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.8-5.el5.centos" test_ref="oval:org.mitre.oval:tst:91287"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21004" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0614: xulrunner security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0614-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0614.html"/>
        <reference source="CESA" ref_id="CESA-2013:0614"/>
        <reference source="CVE" ref_id="CVE-2013-0787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0787.html"/>
        <description>Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:34.917-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:53.904-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:04.718-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:90919"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:90537"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.el6.centos" test_ref="oval:org.mitre.oval:tst:92208"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.el6.centos" test_ref="oval:org.mitre.oval:tst:92041"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:90718"/>
            <criterion comment="xulrunner is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:90957"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21003" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0506: samba4 security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0506-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0506.html"/>
        <reference source="CESA" ref_id="CESA-2013:0506"/>
        <reference source="CVE" ref_id="CVE-2012-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1182.html"/>
        <description>The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a manner consistent with validation of array memory allocation, which allows remote attackers to execute arbitrary code via a crafted RPC call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:29.543-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:53.799-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:04.565-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90302"/>
          <criterion comment="samba4-python is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90614"/>
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90427"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90413"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90535"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90524"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90400"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90429"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:89674"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90583"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90271"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90176"/>
          <criterion comment="samba4 is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:90520"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-55.el6.rc4" test_ref="oval:org.mitre.oval:tst:89874"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21002" version="406" class="patch">
      <metadata>
        <title>RHSA-2012:1467: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1467-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1467.html"/>
        <reference source="CVE" ref_id="CVE-2011-3544" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3544.html"/>
        <reference source="CVE" ref_id="CVE-2012-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1531.html"/>
        <reference source="CVE" ref_id="CVE-2012-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1532.html"/>
        <reference source="CVE" ref_id="CVE-2012-1533" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1533.html"/>
        <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
        <reference source="CVE" ref_id="CVE-2012-3143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3143.html"/>
        <reference source="CVE" ref_id="CVE-2012-3159" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3159.html"/>
        <reference source="CVE" ref_id="CVE-2012-3216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3216.html"/>
        <reference source="CVE" ref_id="CVE-2012-4820" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4820.html"/>
        <reference source="CVE" ref_id="CVE-2012-4821" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4821.html"/>
        <reference source="CVE" ref_id="CVE-2012-4822" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4822.html"/>
        <reference source="CVE" ref_id="CVE-2012-4823" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4823.html"/>
        <reference source="CVE" ref_id="CVE-2012-5067" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5067.html"/>
        <reference source="CVE" ref_id="CVE-2012-5069" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5069.html"/>
        <reference source="CVE" ref_id="CVE-2012-5070" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5070.html"/>
        <reference source="CVE" ref_id="CVE-2012-5071" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5071.html"/>
        <reference source="CVE" ref_id="CVE-2012-5072" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5072.html"/>
        <reference source="CVE" ref_id="CVE-2012-5073" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5073.html"/>
        <reference source="CVE" ref_id="CVE-2012-5074" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5074.html"/>
        <reference source="CVE" ref_id="CVE-2012-5075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5075.html"/>
        <reference source="CVE" ref_id="CVE-2012-5076" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5076.html"/>
        <reference source="CVE" ref_id="CVE-2012-5077" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5077.html"/>
        <reference source="CVE" ref_id="CVE-2012-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5079.html"/>
        <reference source="CVE" ref_id="CVE-2012-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5081.html"/>
        <reference source="CVE" ref_id="CVE-2012-5083" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5083.html"/>
        <reference source="CVE" ref_id="CVE-2012-5084" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5084.html"/>
        <reference source="CVE" ref_id="CVE-2012-5086" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5086.html"/>
        <reference source="CVE" ref_id="CVE-2012-5087" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5087.html"/>
        <reference source="CVE" ref_id="CVE-2012-5088" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5088.html"/>
        <reference source="CVE" ref_id="CVE-2012-5089" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5089.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "IIOP type reuse management" in ObjectStreamClass.java.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:36.173-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:25.655-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:42.237-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:94786"/>
          <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:94705"/>
          <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:94919"/>
          <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:94186"/>
          <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:93954"/>
          <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.3.0-1jpp.2.el6_3" test_ref="oval:org.mitre.oval:tst:94739"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21001" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0668: boost security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>boost</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0668-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0668.html"/>
        <reference source="CESA" ref_id="CESA-2013:0668"/>
        <reference source="CVE" ref_id="CVE-2012-2677" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2677.html"/>
        <description>Integer overflow in the ordered_malloc function in boost/pool/pool.hpp in Boost Pool before 3.9 makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large memory chunk size value, which causes less memory to be allocated than expected.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:33.316-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:53.648-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:04.323-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="boost-graph-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90648"/>
            <criterion comment="boost-graph-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90849"/>
            <criterion comment="boost-mpich2 is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91061"/>
            <criterion comment="boost-test is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91041"/>
            <criterion comment="boost-graph is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90792"/>
            <criterion comment="boost is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90847"/>
            <criterion comment="boost-mpich2-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91036"/>
            <criterion comment="boost-wave is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90430"/>
            <criterion comment="boost-filesystem is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90591"/>
            <criterion comment="boost-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91046"/>
            <criterion comment="boost-thread is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90564"/>
            <criterion comment="boost-mpich2-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90892"/>
            <criterion comment="boost-openmpi is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90304"/>
            <criterion comment="boost-static is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90763"/>
            <criterion comment="boost-doc is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91047"/>
            <criterion comment="boost-regex is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90790"/>
            <criterion comment="boost-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90922"/>
            <criterion comment="boost-openmpi-devel is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90867"/>
            <criterion comment="boost-serialization is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90888"/>
            <criterion comment="boost-system is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91086"/>
            <criterion comment="boost-iostreams is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90569"/>
            <criterion comment="boost-signals is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90092"/>
            <criterion comment="boost-program-options is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90945"/>
            <criterion comment="boost-openmpi-python is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:91002"/>
            <criterion comment="boost-date-time is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90972"/>
            <criterion comment="boost-math is earlier than 0:1.41.0-15.el6_4" test_ref="oval:org.mitre.oval:tst:90372"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="boost is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:90822"/>
            <criterion comment="boost-doc is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:90623"/>
            <criterion comment="boost-devel is earlier than 0:1.33.1-16.el5_9" test_ref="oval:org.mitre.oval:tst:91003"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:21000" version="129" class="patch">
      <metadata>
        <title>RHSA-2013:0219: mysql security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0219-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0219.html"/>
        <reference source="CESA" ref_id="CESA-2013:0219"/>
        <reference source="CVE" ref_id="CVE-2012-0572" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0572.html"/>
        <reference source="CVE" ref_id="CVE-2012-0574" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0574.html"/>
        <reference source="CVE" ref_id="CVE-2012-1702" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1702.html"/>
        <reference source="CVE" ref_id="CVE-2012-1705" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1705.html"/>
        <reference source="CVE" ref_id="CVE-2013-0375" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0375.html"/>
        <reference source="CVE" ref_id="CVE-2013-0383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0383.html"/>
        <reference source="CVE" ref_id="CVE-2013-0384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0384.html"/>
        <reference source="CVE" ref_id="CVE-2013-0385" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0385.html"/>
        <reference source="CVE" ref_id="CVE-2013-0389" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0389.html"/>
        <description>Unspecified vulnerability in the Server component in Oracle MySQL 5.1.66 and earlier, and 5.5.28 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:02.389-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:53.262-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:03.932-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-server is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:90281"/>
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:90415"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:90065"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:90078"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:90134"/>
          <criterion comment="mysql-test is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:90262"/>
          <criterion comment="mysql is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:90482"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.67-1.el6_3" test_ref="oval:org.mitre.oval:tst:90339"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20996" version="172" class="patch">
      <metadata>
        <title>RHSA-2012:1019: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1019-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1019.html"/>
        <reference source="CVE" ref_id="CVE-2012-0551" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0551.html"/>
        <reference source="CVE" ref_id="CVE-2012-1711" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1711.html"/>
        <reference source="CVE" ref_id="CVE-2012-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1713.html"/>
        <reference source="CVE" ref_id="CVE-2012-1716" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1716.html"/>
        <reference source="CVE" ref_id="CVE-2012-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1717.html"/>
        <reference source="CVE" ref_id="CVE-2012-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1718.html"/>
        <reference source="CVE" ref_id="CVE-2012-1719" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1719.html"/>
        <reference source="CVE" ref_id="CVE-2012-1721" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1721.html"/>
        <reference source="CVE" ref_id="CVE-2012-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1722.html"/>
        <reference source="CVE" ref_id="CVE-2012-1723" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1723.html"/>
        <reference source="CVE" ref_id="CVE-2012-1724" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1724.html"/>
        <reference source="CVE" ref_id="CVE-2012-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1725.html"/>
        <reference source="CVE" ref_id="CVE-2012-1726" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1726.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:43.114-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:25.183-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:41.531-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:93418"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:93929"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:93454"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:94040"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.5-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:93931"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20994" version="59" class="patch">
      <metadata>
        <title>RHSA-2013:0685: perl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0685-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0685.html"/>
        <reference source="CESA" ref_id="CESA-2013:0685"/>
        <reference source="CVE" ref_id="CVE-2012-5195" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5195.html"/>
        <reference source="CVE" ref_id="CVE-2012-5526" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5526.html"/>
        <reference source="CVE" ref_id="CVE-2012-6329" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6329.html"/>
        <reference source="CVE" ref_id="CVE-2013-1667" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1667.html"/>
        <description>The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:41.927-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:52.725-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:03.149-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="perl-libs is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:91075"/>
            <criterion comment="perl-suidperl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:90908"/>
            <criterion comment="perl-core is earlier than 0:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:90425"/>
            <criterion comment="perl-Package-Constants is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:91084"/>
            <criterion comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-130.el6_4" test_ref="oval:org.mitre.oval:tst:91083"/>
            <criterion comment="perl-IO-Compress-Base is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90250"/>
            <criterion comment="perl-Time-HiRes is earlier than 4:1.9721-130.el6_4" test_ref="oval:org.mitre.oval:tst:90221"/>
            <criterion comment="perl-CGI is earlier than 0:3.51-130.el6_4" test_ref="oval:org.mitre.oval:tst:90508"/>
            <criterion comment="perl-Log-Message-Simple is earlier than 0:0.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:91060"/>
            <criterion comment="perl-Archive-Extract is earlier than 1:0.38-130.el6_4" test_ref="oval:org.mitre.oval:tst:90881"/>
            <criterion comment="perl-version is earlier than 3:0.77-130.el6_4" test_ref="oval:org.mitre.oval:tst:90582"/>
            <criterion comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-130.el6_4" test_ref="oval:org.mitre.oval:tst:90820"/>
            <criterion comment="perl-Test-Simple is earlier than 0:0.92-130.el6_4" test_ref="oval:org.mitre.oval:tst:90507"/>
            <criterion comment="perl-Compress-Raw-Zlib is earlier than 1:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90612"/>
            <criterion comment="perl-Module-Loaded is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:90741"/>
            <criterion comment="perl-IO-Compress-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90984"/>
            <criterion comment="perl-Module-Pluggable is earlier than 1:3.90-130.el6_4" test_ref="oval:org.mitre.oval:tst:90853"/>
            <criterion comment="perl-Test-Harness is earlier than 0:3.17-130.el6_4" test_ref="oval:org.mitre.oval:tst:90798"/>
            <criterion comment="perl-Pod-Escapes is earlier than 1:1.04-130.el6_4" test_ref="oval:org.mitre.oval:tst:90744"/>
            <criterion comment="perl-parent is earlier than 1:0.221-130.el6_4" test_ref="oval:org.mitre.oval:tst:90958"/>
            <criterion comment="perl-IO-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90727"/>
            <criterion comment="perl-CPANPLUS is earlier than 0:0.88-130.el6_4" test_ref="oval:org.mitre.oval:tst:91021"/>
            <criterion comment="perl-Pod-Simple is earlier than 1:3.13-130.el6_4" test_ref="oval:org.mitre.oval:tst:90796"/>
            <criterion comment="perl-Module-Load is earlier than 1:0.16-130.el6_4" test_ref="oval:org.mitre.oval:tst:90826"/>
            <criterion comment="perl-File-Fetch is earlier than 0:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:90559"/>
            <criterion comment="perl-Module-CoreList is earlier than 0:2.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:90754"/>
            <criterion comment="perl-IO-Zlib is earlier than 1:1.09-130.el6_4" test_ref="oval:org.mitre.oval:tst:90096"/>
            <criterion comment="perl-Params-Check is earlier than 1:0.26-130.el6_4" test_ref="oval:org.mitre.oval:tst:90786"/>
            <criterion comment="perl-Compress-Zlib is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90315"/>
            <criterion comment="perl is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:90538"/>
            <criterion comment="perl-Module-Load-Conditional is earlier than 0:0.30-130.el6_4" test_ref="oval:org.mitre.oval:tst:91057"/>
            <criterion comment="perl-Digest-SHA is earlier than 1:5.47-130.el6_4" test_ref="oval:org.mitre.oval:tst:90376"/>
            <criterion comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-130.el6_4" test_ref="oval:org.mitre.oval:tst:90962"/>
            <criterion comment="perl-Time-Piece is earlier than 0:1.15-130.el6_4" test_ref="oval:org.mitre.oval:tst:90607"/>
            <criterion comment="perl-Archive-Tar is earlier than 0:1.58-130.el6_4" test_ref="oval:org.mitre.oval:tst:91071"/>
            <criterion comment="perl-devel is earlier than 4:5.10.1-130.el6_4" test_ref="oval:org.mitre.oval:tst:90817"/>
            <criterion comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-130.el6_4" test_ref="oval:org.mitre.oval:tst:90961"/>
            <criterion comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-130.el6_4" test_ref="oval:org.mitre.oval:tst:90581"/>
            <criterion comment="perl-Module-Build is earlier than 1:0.3500-130.el6_4" test_ref="oval:org.mitre.oval:tst:90924"/>
            <criterion comment="perl-IPC-Cmd is earlier than 1:0.56-130.el6_4" test_ref="oval:org.mitre.oval:tst:90959"/>
            <criterion comment="perl-CPAN is earlier than 0:1.9402-130.el6_4" test_ref="oval:org.mitre.oval:tst:91090"/>
            <criterion comment="perl-Term-UI is earlier than 0:0.20-130.el6_4" test_ref="oval:org.mitre.oval:tst:91026"/>
            <criterion comment="perl-ExtUtils-Embed is earlier than 0:1.28-130.el6_4" test_ref="oval:org.mitre.oval:tst:90952"/>
            <criterion comment="perl-Object-Accessor is earlier than 1:0.34-130.el6_4" test_ref="oval:org.mitre.oval:tst:90229"/>
            <criterion comment="perl-Compress-Raw-Bzip2 is earlier than 0:2.020-130.el6_4" test_ref="oval:org.mitre.oval:tst:90544"/>
            <criterion comment="perl-Log-Message is earlier than 1:0.02-130.el6_4" test_ref="oval:org.mitre.oval:tst:90712"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="perl-suidperl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:91032"/>
            <criterion comment="perl is earlier than 4:5.8.8-40.el5_9" test_ref="oval:org.mitre.oval:tst:91080"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20993" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0503: 389-ds-base security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0503-03" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0503.html"/>
        <reference source="CESA" ref_id="CESA-2013:0503"/>
        <reference source="CVE" ref_id="CVE-2012-4450" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4450.html"/>
        <description>389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users with certain permissions to bypass ACL restrictions and access the DN entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:09.319-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:52.627-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:02.987-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-11.el6" test_ref="oval:org.mitre.oval:tst:90584"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-11.el6" test_ref="oval:org.mitre.oval:tst:90120"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-11.el6" test_ref="oval:org.mitre.oval:tst:89668"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20992" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0532: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0532-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0532.html"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <reference source="CVE" ref_id="CVE-2013-1484" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1484.html"/>
        <reference source="CVE" ref_id="CVE-2013-1485" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1485.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <reference source="CVE" ref_id="CVE-2013-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1487.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 and earlier and 6 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:23.917-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:52.410-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:02.710-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:89966"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90543"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90514"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90698"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90532"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.15-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90678"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20991" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0869: tomcat6 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0869-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0869.html"/>
        <reference source="CESA" ref_id="CESA-2013:0869"/>
        <reference source="CVE" ref_id="CVE-2013-1976" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1976.html"/>
        <reference source="CVE" ref_id="CVE-2013-2051" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2051.html"/>
        <description>The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale.  NOTE: this issue is due to an incomplete fix for CVE-2012-5887.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:50.502-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:52.255-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:02.525-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:91039"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:91307"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:91127"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:90906"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:90981"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:91303"/>
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:91135"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:90731"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-55.el6_4" test_ref="oval:org.mitre.oval:tst:90632"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20990" version="213" class="patch">
      <metadata>
        <title>RHSA-2013:0744: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0744-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0744.html"/>
        <reference source="CESA" ref_id="CESA-2013:0744"/>
        <reference source="CVE" ref_id="CVE-2012-6537" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6537.html"/>
        <reference source="CVE" ref_id="CVE-2012-6538" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6538.html"/>
        <reference source="CVE" ref_id="CVE-2012-6546" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6546.html"/>
        <reference source="CVE" ref_id="CVE-2012-6547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6547.html"/>
        <reference source="CVE" ref_id="CVE-2013-0349" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0349.html"/>
        <reference source="CVE" ref_id="CVE-2013-0913" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0913.html"/>
        <reference source="CVE" ref_id="CVE-2013-1767" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1767.html"/>
        <reference source="CVE" ref_id="CVE-2013-1773" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1773.html"/>
        <reference source="CVE" ref_id="CVE-2013-1774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1774.html"/>
        <reference source="CVE" ref_id="CVE-2013-1792" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1792.html"/>
        <reference source="CVE" ref_id="CVE-2013-1796" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1796.html"/>
        <reference source="CVE" ref_id="CVE-2013-1797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1797.html"/>
        <reference source="CVE" ref_id="CVE-2013-1798" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1798.html"/>
        <reference source="CVE" ref_id="CVE-2013-1826" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1826.html"/>
        <reference source="CVE" ref_id="CVE-2013-1827" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1827.html"/>
        <description>net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:16.826-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:51.666-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:01.819-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:91227"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:91129"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:91141"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:90700"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:90832"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:90252"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:91226"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:90839"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:90784"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:91118"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:90414"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.6.1.el6" test_ref="oval:org.mitre.oval:tst:90793"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20988" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0499: xinetd security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>xinetd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0499-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0499.html"/>
        <reference source="CESA" ref_id="CESA-2013:0499"/>
        <reference source="CVE" ref_id="CVE-2012-0862" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0862.html"/>
        <description>builtins.c in Xinetd before 2.3.15 does not check the service type when the tcpmux-server service is enabled, which exposes all enabled services and allows remote attackers to bypass intended access restrictions via a request to tcpmux port 1.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:14.900-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:51.562-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:01.639-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="xinetd is earlier than 2:2.3.14-38.el6" test_ref="oval:org.mitre.oval:tst:90321"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20985" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0199: libvirt security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0199-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0199.html"/>
        <reference source="CESA" ref_id="CESA-2013:0199"/>
        <reference source="CVE" ref_id="CVE-2013-0170" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0170.html"/>
        <description>Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:41.135-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:51.321-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:01.348-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.el6_3.8" test_ref="oval:org.mitre.oval:tst:90082"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.el6_3.8" test_ref="oval:org.mitre.oval:tst:90490"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.el6_3.8" test_ref="oval:org.mitre.oval:tst:90464"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.9.10-21.el6_3.8" test_ref="oval:org.mitre.oval:tst:90152"/>
          <criterion comment="libvirt is earlier than 0:0.9.10-21.el6_3.8" test_ref="oval:org.mitre.oval:tst:90408"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20984" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0508: sssd security, bug fix and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0508-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0508.html"/>
        <reference source="CESA" ref_id="CESA-2013:0508"/>
        <reference source="CVE" ref_id="CVE-2013-0219" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0219.html"/>
        <reference source="CVE" ref_id="CVE-2013-0220" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0220.html"/>
        <description>The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Services Daemon (SSSD) before 1.9.4 allow remote attackers to cause a denial of service (out-of-bounds read, crash, and restart) via a crafted SSSD packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:14.058-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:51.202-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:01.176-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="sssd-client is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90480"/>
          <criterion comment="libipa_hbac-python is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90658"/>
          <criterion comment="libsss_sudo is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90145"/>
          <criterion comment="sssd is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90323"/>
          <criterion comment="libipa_hbac is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90003"/>
          <criterion comment="libsss_idmap is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90577"/>
          <criterion comment="libsss_autofs is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90386"/>
          <criterion comment="libipa_hbac-devel is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90342"/>
          <criterion comment="sssd-tools is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90493"/>
          <criterion comment="libsss_idmap-devel is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90616"/>
          <criterion comment="libsss_sudo-devel is earlier than 0:1.9.2-82.el6" test_ref="oval:org.mitre.oval:tst:90016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20983" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0514: php security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0514-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0514.html"/>
        <reference source="CESA" ref_id="CESA-2013:0514"/>
        <reference source="CVE" ref_id="CVE-2011-1398" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1398.html"/>
        <reference source="CVE" ref_id="CVE-2012-0831" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0831.html"/>
        <reference source="CVE" ref_id="CVE-2012-2688" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2688.html"/>
        <description>Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an "overflow."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:41.758-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:51.015-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:00.842-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="php-pdo is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90693"/>
          <criterion comment="php-common is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90625"/>
          <criterion comment="php-pgsql is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90085"/>
          <criterion comment="php-xmlrpc is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90317"/>
          <criterion comment="php-snmp is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:89898"/>
          <criterion comment="php-enchant is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90696"/>
          <criterion comment="php-embedded is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:89719"/>
          <criterion comment="php-devel is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90073"/>
          <criterion comment="php-recode is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90326"/>
          <criterion comment="php is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90573"/>
          <criterion comment="php-odbc is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90409"/>
          <criterion comment="php-gd is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90656"/>
          <criterion comment="php-imap is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90715"/>
          <criterion comment="php-tidy is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90587"/>
          <criterion comment="php-fpm is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90597"/>
          <criterion comment="php-soap is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90238"/>
          <criterion comment="php-mysql is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90661"/>
          <criterion comment="php-bcmath is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90589"/>
          <criterion comment="php-process is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90628"/>
          <criterion comment="php-intl is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90717"/>
          <criterion comment="php-zts is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90245"/>
          <criterion comment="php-mbstring is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90276"/>
          <criterion comment="php-ldap is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90040"/>
          <criterion comment="php-cli is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90346"/>
          <criterion comment="php-dba is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90030"/>
          <criterion comment="php-xml is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90556"/>
          <criterion comment="php-pspell is earlier than 0:5.3.3-22.el6" test_ref="oval:org.mitre.oval:tst:90622"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20981" version="311" class="patch">
      <metadata>
        <title>RHSA-2013:0247: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0247-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0247.html"/>
        <reference source="CESA" ref_id="CESA-2013:0247"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0429.html"/>
        <reference source="CVE" ref_id="CVE-2013-0431" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0431.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0435.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0441.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0444.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:46.461-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:50.461-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:00.680-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:89907"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:90463"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:90394"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:90351"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.5.3.el6_3" test_ref="oval:org.mitre.oval:tst:90318"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:90195"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:90371"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:90410"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:90439"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.5.3.el5_9" test_ref="oval:org.mitre.oval:tst:90462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20979" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0500: hplip security, bug fix and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>hplip</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0500-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0500.html"/>
        <reference source="CESA" ref_id="CESA-2013:0500"/>
        <reference source="CVE" ref_id="CVE-2011-2722" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2722.html"/>
        <reference source="CVE" ref_id="CVE-2013-0200" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0200.html"/>
        <description>HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:44.747-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:50.135-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:00.507-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libsane-hpaio is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:90407"/>
          <criterion comment="hplip-libs is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:90481"/>
          <criterion comment="hplip is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:90603"/>
          <criterion comment="hplip-common is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:90566"/>
          <criterion comment="hpijs is earlier than 1:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:90190"/>
          <criterion comment="hplip-gui is earlier than 0:3.12.4-4.el6" test_ref="oval:org.mitre.oval:tst:90131"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20978" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0669: qt security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0669-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0669.html"/>
        <reference source="CESA" ref_id="CESA-2013:0669"/>
        <reference source="CVE" ref_id="CVE-2013-0254" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0254.html"/>
        <description>The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:26.168-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:50.022-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:01:00.309-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qt-demos is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:90473"/>
          <criterion comment="qt-odbc is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:90399"/>
          <criterion comment="qt-mysql is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:90761"/>
          <criterion comment="qt-x11 is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:91062"/>
          <criterion comment="qt-doc is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:90993"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:90973"/>
          <criterion comment="qt-sqlite is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:90548"/>
          <criterion comment="qt-postgresql is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:90833"/>
          <criterion comment="qt is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:91044"/>
          <criterion comment="qt-devel is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:90974"/>
          <criterion comment="qt-examples is earlier than 1:4.6.2-26.el6_4" test_ref="oval:org.mitre.oval:tst:90873"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20976" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0324: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0324-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0324.html"/>
        <reference source="CESA" ref_id="CESA-2012:0324"/>
        <reference source="CVE" ref_id="CVE-2012-0841" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0841.html"/>
        <description>libxml2 before 2.8.0 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:25.669-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:24.724-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:41.189-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:92439"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:93061"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.2" test_ref="oval:org.mitre.oval:tst:92745"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:93069"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:93014"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:93032"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-4.el6_2.4" test_ref="oval:org.mitre.oval:tst:92829"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20975" version="4" class="patch">
      <metadata>
        <title>RHSA-2011:0677: openssl security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0677-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0677.html"/>
        <reference source="CVE" ref_id="CVE-2011-0014" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0014.html"/>
        <description>ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:54.554-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:24.616-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:41.021-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="openssl-devel is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:98064"/>
          <criterion comment="openssl-static is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:97399"/>
          <criterion comment="openssl-perl is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:97538"/>
          <criterion comment="openssl is earlier than 0:1.0.0-10.el6" test_ref="oval:org.mitre.oval:tst:97688"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20972" version="94" class="patch">
      <metadata>
        <title>RHSA-2012:0469: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0469-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0469.html"/>
        <reference source="CVE" ref_id="CVE-2011-4370" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4370.html"/>
        <reference source="CVE" ref_id="CVE-2011-4371" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4371.html"/>
        <reference source="CVE" ref_id="CVE-2011-4372" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4372.html"/>
        <reference source="CVE" ref_id="CVE-2011-4373" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4373.html"/>
        <reference source="CVE" ref_id="CVE-2012-0774" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0774.html"/>
        <reference source="CVE" ref_id="CVE-2012-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0775.html"/>
        <reference source="CVE" ref_id="CVE-2012-0777" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0777.html"/>
        <description>The JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 on Mac OS X and Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:46.262-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:24.354-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:40.728-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.5.1-1.el5" test_ref="oval:org.mitre.oval:tst:92957"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.1-1.el5" test_ref="oval:org.mitre.oval:tst:93105"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.5.1-1.el6_2" test_ref="oval:org.mitre.oval:tst:92952"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.1-1.el6_2" test_ref="oval:org.mitre.oval:tst:93278"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20971" version="199" class="patch">
      <metadata>
        <title>RHSA-2013:0772: mysql security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mysql</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0772-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0772.html"/>
        <reference source="CESA" ref_id="CESA-2013:0772"/>
        <reference source="CVE" ref_id="CVE-2012-5614" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5614.html"/>
        <reference source="CVE" ref_id="CVE-2013-1506" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1506.html"/>
        <reference source="CVE" ref_id="CVE-2013-1521" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1521.html"/>
        <reference source="CVE" ref_id="CVE-2013-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1531.html"/>
        <reference source="CVE" ref_id="CVE-2013-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1532.html"/>
        <reference source="CVE" ref_id="CVE-2013-1544" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1544.html"/>
        <reference source="CVE" ref_id="CVE-2013-1548" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1548.html"/>
        <reference source="CVE" ref_id="CVE-2013-1552" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1552.html"/>
        <reference source="CVE" ref_id="CVE-2013-1555" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1555.html"/>
        <reference source="CVE" ref_id="CVE-2013-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2375.html"/>
        <reference source="CVE" ref_id="CVE-2013-2378" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2378.html"/>
        <reference source="CVE" ref_id="CVE-2013-2389" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2389.html"/>
        <reference source="CVE" ref_id="CVE-2013-2391" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2391.html"/>
        <reference source="CVE" ref_id="CVE-2013-2392" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2392.html"/>
        <description>Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:12.146-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:49.269-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:59.813-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mysql-embedded-devel is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:91255"/>
          <criterion comment="mysql-server is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:91157"/>
          <criterion comment="mysql-bench is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:90289"/>
          <criterion comment="mysql-libs is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:91185"/>
          <criterion comment="mysql-embedded is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:90746"/>
          <criterion comment="mysql-test is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:90574"/>
          <criterion comment="mysql is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:91105"/>
          <criterion comment="mysql-devel is earlier than 0:5.1.69-1.el6_4" test_ref="oval:org.mitre.oval:tst:90943"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20967" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0188: ipa security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ipa</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0188-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0188.html"/>
        <reference source="CESA" ref_id="CESA-2013:0188"/>
        <reference source="CVE" ref_id="CVE-2012-5484" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5484.html"/>
        <description>The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to spoof a join procedure via a crafted certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:53.268-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:48.920-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:59.399-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ipa-python is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:90068"/>
          <criterion comment="ipa-admintools is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:90446"/>
          <criterion comment="ipa-client is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:90360"/>
          <criterion comment="ipa-server-selinux is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:90071"/>
          <criterion comment="ipa-server is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:90348"/>
          <criterion comment="ipa is earlier than 0:2.2.0-17.el6_3.1" test_ref="oval:org.mitre.oval:tst:90313"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20962" version="121" class="patch">
      <metadata>
        <title>RHSA-2011:0364: java-1.5.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0364-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0364.html"/>
        <reference source="CVE" ref_id="CVE-2010-4447" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4447.html"/>
        <reference source="CVE" ref_id="CVE-2010-4448" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4448.html"/>
        <reference source="CVE" ref_id="CVE-2010-4450" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4450.html"/>
        <reference source="CVE" ref_id="CVE-2010-4454" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4454.html"/>
        <reference source="CVE" ref_id="CVE-2010-4462" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4462.html"/>
        <reference source="CVE" ref_id="CVE-2010-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4465.html"/>
        <reference source="CVE" ref_id="CVE-2010-4466" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4466.html"/>
        <reference source="CVE" ref_id="CVE-2010-4468" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4468.html"/>
        <reference source="CVE" ref_id="CVE-2010-4471" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4471.html"/>
        <reference source="CVE" ref_id="CVE-2010-4473" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4473.html"/>
        <reference source="CVE" ref_id="CVE-2010-4475" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4475.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:20.030-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:23.923-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:40.335-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97441"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:96650"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97649"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97280"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97536"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97409"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97595"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el5" test_ref="oval:org.mitre.oval:tst:97394"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:96679"/>
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:96667"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97335"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97581"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97667"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97546"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.4-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:97609"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20955" version="591" class="patch">
      <metadata>
        <title>RHSA-2013:0757: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0757-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0757.html"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-0402" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0402.html"/>
        <reference source="CVE" ref_id="CVE-2013-1488" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1488.html"/>
        <reference source="CVE" ref_id="CVE-2013-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1491.html"/>
        <reference source="CVE" ref_id="CVE-2013-1518" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1518.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1540" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1540.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1558.html"/>
        <reference source="CVE" ref_id="CVE-2013-1561" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1561.html"/>
        <reference source="CVE" ref_id="CVE-2013-1563" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1563.html"/>
        <reference source="CVE" ref_id="CVE-2013-1564" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1564.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2394" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2394.html"/>
        <reference source="CVE" ref_id="CVE-2013-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2414.html"/>
        <reference source="CVE" ref_id="CVE-2013-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2415.html"/>
        <reference source="CVE" ref_id="CVE-2013-2416" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2416.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2418" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2418.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2421.html"/>
        <reference source="CVE" ref_id="CVE-2013-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2422.html"/>
        <reference source="CVE" ref_id="CVE-2013-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2423.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2425.html"/>
        <reference source="CVE" ref_id="CVE-2013-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2426.html"/>
        <reference source="CVE" ref_id="CVE-2013-2427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2427.html"/>
        <reference source="CVE" ref_id="CVE-2013-2428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2428.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2431" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2431.html"/>
        <reference source="CVE" ref_id="CVE-2013-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2432.html"/>
        <reference source="CVE" ref_id="CVE-2013-2433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2433.html"/>
        <reference source="CVE" ref_id="CVE-2013-2434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2434.html"/>
        <reference source="CVE" ref_id="CVE-2013-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2435.html"/>
        <reference source="CVE" ref_id="CVE-2013-2436" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2436.html"/>
        <reference source="CVE" ref_id="CVE-2013-2438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2438.html"/>
        <reference source="CVE" ref_id="CVE-2013-2439" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2439.html"/>
        <reference source="CVE" ref_id="CVE-2013-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2440.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:18.581-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:46.924-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:57.303-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:91201"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:90807"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:91052"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:91000"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:91100"/>
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.21-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:90907"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20947" version="507" class="patch">
      <metadata>
        <title>RHSA-2013:0237: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0237-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0237.html"/>
        <reference source="CVE" ref_id="CVE-2012-1541" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1541.html"/>
        <reference source="CVE" ref_id="CVE-2012-3213" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3213.html"/>
        <reference source="CVE" ref_id="CVE-2012-3342" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3342.html"/>
        <reference source="CVE" ref_id="CVE-2013-0351" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0351.html"/>
        <reference source="CVE" ref_id="CVE-2013-0409" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0409.html"/>
        <reference source="CVE" ref_id="CVE-2013-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0419.html"/>
        <reference source="CVE" ref_id="CVE-2013-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0423.html"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0429.html"/>
        <reference source="CVE" ref_id="CVE-2013-0430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0430.html"/>
        <reference source="CVE" ref_id="CVE-2013-0431" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0431.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0435.html"/>
        <reference source="CVE" ref_id="CVE-2013-0437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0437.html"/>
        <reference source="CVE" ref_id="CVE-2013-0438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0438.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0441.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0444.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0446.html"/>
        <reference source="CVE" ref_id="CVE-2013-0448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0448.html"/>
        <reference source="CVE" ref_id="CVE-2013-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0449.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-1473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1473.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1479" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1479.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <reference source="CVE" ref_id="CVE-2013-1489" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1489.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 10 and Update 11, when running on Windows using Internet Explorer, Firefox, Opera, and Google Chrome, allows remote attackers to bypass the "Very High" security level of the Java Control Panel and execute unsigned Java code without prompting the user via unknown vectors, aka "Issue 53" and the "Java Security Slider" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:12.426-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:45.167-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:55.761-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90268"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:89769"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90396"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90335"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90292"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.13-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20946" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0522: gdb security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>gdb</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0522-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0522.html"/>
        <reference source="CESA" ref_id="CESA-2013:0522"/>
        <reference source="CVE" ref_id="CVE-2011-4355" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4355.html"/>
        <description>GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:05.564-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:45.023-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:55.654-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gdb-gdbserver is earlier than 0:7.2-60.el6" test_ref="oval:org.mitre.oval:tst:90579"/>
          <criterion comment="gdb is earlier than 0:7.2-60.el6" test_ref="oval:org.mitre.oval:tst:90227"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20942" version="47" class="patch">
      <metadata>
        <title>RHSA-2013:1035: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1035-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1035.html"/>
        <reference source="CVE" ref_id="CVE-2013-3344" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3344.html"/>
        <reference source="CVE" ref_id="CVE-2013-3345" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3345.html"/>
        <reference source="CVE" ref_id="CVE-2013-3347" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3347.html"/>
        <description>Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Linux, before 11.1.111.64 on Android 2.x and 3.x, and before 11.1.115.69 on Android 4.x allows attackers to execute arbitrary code via PCM data that is not properly handled during resampling.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:43.079-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:44.861-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:55.492-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20942 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:13.742-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:23.543-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.297-1.el5" test_ref="oval:org.mitre.oval:tst:137761"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.297-1.el6" test_ref="oval:org.mitre.oval:tst:91097"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20940" version="224" class="patch">
      <metadata>
        <title>RHSA-2012:0034: java-1.6.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0034-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0034.html"/>
        <reference source="CVE" ref_id="CVE-2011-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3389.html"/>
        <reference source="CVE" ref_id="CVE-2011-3516" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3516.html"/>
        <reference source="CVE" ref_id="CVE-2011-3521" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3521.html"/>
        <reference source="CVE" ref_id="CVE-2011-3544" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3544.html"/>
        <reference source="CVE" ref_id="CVE-2011-3545" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3545.html"/>
        <reference source="CVE" ref_id="CVE-2011-3546" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3546.html"/>
        <reference source="CVE" ref_id="CVE-2011-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3547.html"/>
        <reference source="CVE" ref_id="CVE-2011-3548" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3548.html"/>
        <reference source="CVE" ref_id="CVE-2011-3549" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3549.html"/>
        <reference source="CVE" ref_id="CVE-2011-3550" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3550.html"/>
        <reference source="CVE" ref_id="CVE-2011-3551" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3551.html"/>
        <reference source="CVE" ref_id="CVE-2011-3552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3552.html"/>
        <reference source="CVE" ref_id="CVE-2011-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3553.html"/>
        <reference source="CVE" ref_id="CVE-2011-3554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3554.html"/>
        <reference source="CVE" ref_id="CVE-2011-3556" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3556.html"/>
        <reference source="CVE" ref_id="CVE-2011-3557" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3557.html"/>
        <reference source="CVE" ref_id="CVE-2011-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3560.html"/>
        <reference source="CVE" ref_id="CVE-2011-3561" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3561.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:51.215-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:22.297-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:38.612-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92500"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92625"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92358"/>
            <criterion comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92727"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92428"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92212"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92489"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.0-1jpp.2.el5" test_ref="oval:org.mitre.oval:tst:92626"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92386"/>
            <criterion comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92465"/>
            <criterion comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92090"/>
            <criterion comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92437"/>
            <criterion comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92341"/>
            <criterion comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92764"/>
            <criterion comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.0-1jpp.2.el6" test_ref="oval:org.mitre.oval:tst:92633"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20938" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:0451: rpm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>rpm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0451-03" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0451.html"/>
        <reference source="CESA" ref_id="CESA-2012:0451"/>
        <reference source="CVE" ref_id="CVE-2012-0060" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0060.html"/>
        <reference source="CVE" ref_id="CVE-2012-0061" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0061.html"/>
        <reference source="CVE" ref_id="CVE-2012-0815" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0815.html"/>
        <description>The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative value in a region offset of a package header, which is not properly handled in a numeric range comparison.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:15.195-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:22.084-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:38.262-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="rpm is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:92975"/>
            <criterion comment="rpm-python is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:93125"/>
            <criterion comment="rpm-libs is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:93265"/>
            <criterion comment="rpm-build is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:92801"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:92865"/>
            <criterion comment="popt is earlier than 0:1.10.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:93340"/>
            <criterion comment="rpm-devel is earlier than 0:4.4.2.3-28.el5_8" test_ref="oval:org.mitre.oval:tst:93007"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="rpm-cron is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93240"/>
            <criterion comment="rpm is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93010"/>
            <criterion comment="rpm-libs is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93066"/>
            <criterion comment="rpm-python is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93306"/>
            <criterion comment="rpm-build is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:92355"/>
            <criterion comment="rpm-apidocs is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93159"/>
            <criterion comment="rpm-devel is earlier than 0:4.8.0-19.el6_2.1" test_ref="oval:org.mitre.oval:tst:93234"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20936" version="42" class="patch">
      <metadata>
        <title>RHSA-2011:0200: krb5 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2011:0200-01" ref_url="https://rhn.redhat.com/errata/RHSA-2011-0200.html"/>
        <reference source="CVE" ref_id="CVE-2010-4022" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4022.html"/>
        <reference source="CVE" ref_id="CVE-2011-0281" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0281.html"/>
        <reference source="CVE" ref_id="CVE-2011-0282" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0282.html"/>
        <description>The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a denial of service (NULL pointer dereference or buffer over-read, and daemon crash) via a crafted principal name.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-15T12:06:21">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:37:26.611-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:21.929-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:38.080-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:97521"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:97329"/>
          <criterion comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:96731"/>
          <criterion comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:96787"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:97516"/>
          <criterion comment="krb5-server is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:96858"/>
          <criterion comment="krb5 is earlier than 0:1.8.2-3.el6_0.4" test_ref="oval:org.mitre.oval:tst:97519"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20933" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0627: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0627-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0627.html"/>
        <reference source="CESA" ref_id="CESA-2013:0627"/>
        <reference source="CVE" ref_id="CVE-2013-0787" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0787.html"/>
        <description>Use-after-free vulnerability in the nsEditor::IsPreformatted function in editor/libeditor/base/nsEditor.cpp in Mozilla Firefox before 19.0.2, Firefox ESR 17.x before 17.0.4, Thunderbird before 17.0.4, Thunderbird ESR 17.x before 17.0.4, and SeaMonkey before 2.16.1 allows remote attackers to execute arbitrary code via vectors involving an execCommand call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:12.255-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:44.589-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:55.219-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:90753"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el6.centos" test_ref="oval:org.mitre.oval:tst:91855"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el5_9" test_ref="oval:org.mitre.oval:tst:90002"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.3-2.el5.centos" test_ref="oval:org.mitre.oval:tst:91615"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20931" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1049: php security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>php</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1049-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1049.html"/>
        <reference source="CESA" ref_id="CESA-2013:1049"/>
        <reference source="CVE" ref_id="CVE-2013-4113" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4113.html"/>
        <description>ext/xml/xml.c in PHP before 5.3.27 does not properly consider parsing depth, which allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted document that is processed by the xml_parse_into_struct function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:58.138-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:44.344-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:54.961-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-embedded is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90523"/>
            <criterion comment="php-xml is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91273"/>
            <criterion comment="php-enchant is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91428"/>
            <criterion comment="php-imap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91400"/>
            <criterion comment="php-mysql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91430"/>
            <criterion comment="php is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91289"/>
            <criterion comment="php-bcmath is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91353"/>
            <criterion comment="php-process is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91426"/>
            <criterion comment="php-intl is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91205"/>
            <criterion comment="php-pdo is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90530"/>
            <criterion comment="php-odbc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90938"/>
            <criterion comment="php-snmp is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91361"/>
            <criterion comment="php-pgsql is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91384"/>
            <criterion comment="php-fpm is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90630"/>
            <criterion comment="php-recode is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91056"/>
            <criterion comment="php-zts is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91264"/>
            <criterion comment="php-tidy is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91417"/>
            <criterion comment="php-soap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91520"/>
            <criterion comment="php-ldap is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91419"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91404"/>
            <criterion comment="php-pspell is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91327"/>
            <criterion comment="php-devel is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91401"/>
            <criterion comment="php-common is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90724"/>
            <criterion comment="php-mbstring is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91299"/>
            <criterion comment="php-cli is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:90667"/>
            <criterion comment="php-dba is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91087"/>
            <criterion comment="php-gd is earlier than 0:5.3.3-23.el6_4" test_ref="oval:org.mitre.oval:tst:91276"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="php-xml is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91453"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91522"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:90570"/>
            <criterion comment="php is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91326"/>
            <criterion comment="php-bcmath is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91510"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91568"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:90704"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91468"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91515"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91305"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91391"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:90823"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91308"/>
            <criterion comment="php-common is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91182"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91322"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91208"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91101"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91423"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-40.el5_9" test_ref="oval:org.mitre.oval:tst:91203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20929" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0516: evolution security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>evolution</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0516-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0516.html"/>
        <reference source="CESA" ref_id="CESA-2013:0516"/>
        <reference source="CVE" ref_id="CVE-2011-3201" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3201.html"/>
        <description>GNOME Evolution before 3.2.3 allows user-assisted remote attackers to read arbitrary files via the attachment parameter to a mailto: URL, which attaches the file to the email.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:25.853-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:44.221-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:54.785-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="evolution is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:90613"/>
          <criterion comment="evolution-devel is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:90477"/>
          <criterion comment="evolution-conduits is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:89741"/>
          <criterion comment="evolution-perl is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:90174"/>
          <criterion comment="evolution-spamassassin is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:89932"/>
          <criterion comment="evolution-pst is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:90600"/>
          <criterion comment="evolution-help is earlier than 0:2.28.3-30.el6" test_ref="oval:org.mitre.oval:tst:90585"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20927" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0509: rdma security, bug fix and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ibacm</product>
          <product>infinipath-psm</product>
          <product>libibmad</product>
          <product>libibumad</product>
          <product>libibverbs</product>
          <product>libmlx4</product>
          <product>librdmacm</product>
          <product>opensm</product>
          <product>rdma</product>
          <product>ibsim</product>
          <product>ibutils</product>
          <product>infiniband-diags</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0509-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0509.html"/>
        <reference source="CESA" ref_id="CESA-2013:0509"/>
        <reference source="CVE" ref_id="CVE-2012-4517" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4517.html"/>
        <reference source="CVE" ref_id="CVE-2012-4518" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4518.html"/>
        <description>ibacm 1.0.7 creates files with world-writable permissions, which allows local users to overwrite the ib_acm daemon log or ibacm.port file.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:36.235-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:43.980-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:54.435-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="infinipath-psm-devel is earlier than 0:3.0.1-115.1015_open.1.el6" test_ref="oval:org.mitre.oval:tst:90222"/>
          <criterion comment="infinipath-psm is earlier than 0:3.0.1-115.1015_open.1.el6" test_ref="oval:org.mitre.oval:tst:90563"/>
          <criterion comment="rdma is earlier than 0:3.6-1.el6" test_ref="oval:org.mitre.oval:tst:90517"/>
          <criterion comment="libibverbs-devel is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:89693"/>
          <criterion comment="libibverbs is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:90385"/>
          <criterion comment="libibverbs-devel-static is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:90525"/>
          <criterion comment="libibverbs-utils is earlier than 0:1.1.6-5.el6" test_ref="oval:org.mitre.oval:tst:90531"/>
          <criterion comment="libmlx4-static is earlier than 0:1.0.4-1.el6" test_ref="oval:org.mitre.oval:tst:90363"/>
          <criterion comment="libmlx4 is earlier than 0:1.0.4-1.el6" test_ref="oval:org.mitre.oval:tst:90052"/>
          <criterion comment="libibumad is earlier than 0:1.3.8-1.el6" test_ref="oval:org.mitre.oval:tst:90594"/>
          <criterion comment="libibumad-devel is earlier than 0:1.3.8-1.el6" test_ref="oval:org.mitre.oval:tst:90288"/>
          <criterion comment="libibumad-static is earlier than 0:1.3.8-1.el6" test_ref="oval:org.mitre.oval:tst:90214"/>
          <criterion comment="libibmad-static is earlier than 0:1.3.9-1.el6" test_ref="oval:org.mitre.oval:tst:90478"/>
          <criterion comment="libibmad is earlier than 0:1.3.9-1.el6" test_ref="oval:org.mitre.oval:tst:90599"/>
          <criterion comment="libibmad-devel is earlier than 0:1.3.9-1.el6" test_ref="oval:org.mitre.oval:tst:90511"/>
          <criterion comment="opensm-static is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:89927"/>
          <criterion comment="opensm is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:90504"/>
          <criterion comment="opensm-devel is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:90606"/>
          <criterion comment="opensm-libs is earlier than 0:3.3.15-1.el6" test_ref="oval:org.mitre.oval:tst:90539"/>
          <criterion comment="ibutils is earlier than 0:1.5.7-7.el6" test_ref="oval:org.mitre.oval:tst:90298"/>
          <criterion comment="ibutils-libs is earlier than 0:1.5.7-7.el6" test_ref="oval:org.mitre.oval:tst:90611"/>
          <criterion comment="ibutils-devel is earlier than 0:1.5.7-7.el6" test_ref="oval:org.mitre.oval:tst:90653"/>
          <criterion comment="ibsim is earlier than 0:0.5-7.el6" test_ref="oval:org.mitre.oval:tst:90451"/>
          <criterion comment="ibacm is earlier than 0:1.0.8-0.git7a3adb7.el6" test_ref="oval:org.mitre.oval:tst:90499"/>
          <criterion comment="ibacm-devel is earlier than 0:1.0.8-0.git7a3adb7.el6" test_ref="oval:org.mitre.oval:tst:89881"/>
          <criterion comment="infiniband-diags-devel-static is earlier than 0:1.5.12-5.el6" test_ref="oval:org.mitre.oval:tst:90575"/>
          <criterion comment="infiniband-diags is earlier than 0:1.5.12-5.el6" test_ref="oval:org.mitre.oval:tst:90275"/>
          <criterion comment="infiniband-diags-devel is earlier than 0:1.5.12-5.el6" test_ref="oval:org.mitre.oval:tst:90624"/>
          <criterion comment="librdmacm-utils is earlier than 0:1.0.17-0.git4b5c1aa.el6" test_ref="oval:org.mitre.oval:tst:90506"/>
          <criterion comment="librdmacm is earlier than 0:1.0.17-0.git4b5c1aa.el6" test_ref="oval:org.mitre.oval:tst:90345"/>
          <criterion comment="librdmacm-static is earlier than 0:1.0.17-0.git4b5c1aa.el6" test_ref="oval:org.mitre.oval:tst:90676"/>
          <criterion comment="librdmacm-devel is earlier than 0:1.0.17-0.git4b5c1aa.el6" test_ref="oval:org.mitre.oval:tst:90489"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20926" version="33" class="patch">
      <metadata>
        <title>RHSA-2013:0243: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0243-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0243.html"/>
        <reference source="CVE" ref_id="CVE-2013-0633" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0633.html"/>
        <reference source="CVE" ref_id="CVE-2013-0634" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0634.html"/>
        <description>Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:28.933-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:43.819-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:54.282-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20926 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:05.823-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:22.936-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.262-1.el5" test_ref="oval:org.mitre.oval:tst:137704"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.262-1.el6" test_ref="oval:org.mitre.oval:tst:89863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20919" version="61" class="patch">
      <metadata>
        <title>RHSA-2013:1256: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1256.html"/>
        <reference source="CVE" ref_id="CVE-2013-3361" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3361.html"/>
        <reference source="CVE" ref_id="CVE-2013-3362" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3362.html"/>
        <reference source="CVE" ref_id="CVE-2013-3363" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3363.html"/>
        <reference source="CVE" ref_id="CVE-2013-5324" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5324.html"/>
        <description>Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK &amp; Compiler before 3.8.0.1430 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3361, CVE-2013-3362, and CVE-2013-3363.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:53.619-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:43.480-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:54.048-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20919 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:31.239-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:22.439-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.310-1.el5" test_ref="oval:org.mitre.oval:tst:137342"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.310-1.el6" test_ref="oval:org.mitre.oval:tst:91058"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20914" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:0095: ghostscript security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0095-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0095.html"/>
        <reference source="CESA" ref_id="CESA-2012:0095"/>
        <reference source="CVE" ref_id="CVE-2009-3743" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3743.html"/>
        <reference source="CVE" ref_id="CVE-2010-2055" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2055.html"/>
        <reference source="CVE" ref_id="CVE-2010-4054" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4054.html"/>
        <reference source="CVE" ref_id="CVE-2010-4820" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4820.html"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:44.378-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:21.608-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:37.555-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:92780"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:93020"/>
            <criterion comment="ghostscript-doc is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:92734"/>
            <criterion comment="ghostscript is earlier than 0:8.70-11.el6_2.6" test_ref="oval:org.mitre.oval:tst:92766"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ghostscript-gtk is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:92620"/>
            <criterion comment="ghostscript-devel is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:92999"/>
            <criterion comment="ghostscript is earlier than 0:8.70-6.el5_7.6" test_ref="oval:org.mitre.oval:tst:92891"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20912" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0277: dnsmasq security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>dnsmasq</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0277-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0277.html"/>
        <reference source="CESA" ref_id="CESA-2013:0277"/>
        <reference source="CVE" ref_id="CVE-2012-3411" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3411.html"/>
        <description>Dnsmasq before 2.63test1, when used with certain libvirt configurations, replies to requests from prohibited interfaces, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed DNS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:01.022-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:43.367-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:53.941-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dnsmasq-utils is earlier than 0:2.48-13.el6" test_ref="oval:org.mitre.oval:tst:90529"/>
          <criterion comment="dnsmasq is earlier than 0:2.48-13.el6" test_ref="oval:org.mitre.oval:tst:90447"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20910" version="6" class="patch">
      <metadata>
        <title>RHSA-2013:0941: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0941-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0941.html"/>
        <reference source="CVE" ref_id="CVE-2013-3343" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3343.html"/>
        <description>Adobe Flash Player before 10.3.183.90 and 11.x before 11.7.700.224 on Windows, before 10.3.183.90 and 11.x before 11.7.700.225 on Mac OS X, before 10.3.183.90 and 11.x before 11.2.202.291 on Linux, before 11.1.111.59 on Android 2.x and 3.x, and before 11.1.115.63 on Android 4.x; Adobe AIR before 3.7.0.2090 on Windows and Android and before 3.7.0.2100 on Mac OS X; and Adobe AIR SDK &amp; Compiler before 3.7.0.2090 on Windows and before 3.7.0.2100 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:27.922-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:43.040-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:53.619-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20910 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:34.240-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:22.117-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.291-1.el5" test_ref="oval:org.mitre.oval:tst:137675"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.291-1.el6" test_ref="oval:org.mitre.oval:tst:91379"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20908" version="87" class="patch">
      <metadata>
        <title>RHSA-2013:0496: Red Hat Enterprise Linux 6 kernel update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0496-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0496.html"/>
        <reference source="CESA" ref_id="CESA-2013:0496"/>
        <reference source="CVE" ref_id="CVE-2012-4508" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4508.html"/>
        <reference source="CVE" ref_id="CVE-2012-4542" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4542.html"/>
        <reference source="CVE" ref_id="CVE-2013-0190" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0190.html"/>
        <reference source="CVE" ref_id="CVE-2013-0309" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0309.html"/>
        <reference source="CVE" ref_id="CVE-2013-0310" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0310.html"/>
        <reference source="CVE" ref_id="CVE-2013-0311" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0311.html"/>
        <description>The translate_desc function in drivers/vhost/vhost.c in the Linux kernel before 3.7 does not properly handle cross-region descriptors, which allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:47.808-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:42.734-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:53.351-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:90428"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:90547"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:90551"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:89613"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:90550"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:90568"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:89842"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:90500"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:90352"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:90516"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:90484"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.el6" test_ref="oval:org.mitre.oval:tst:90426"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20907" version="115" class="patch">
      <metadata>
        <title>RHSA-2013:1269: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1269-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1269.html"/>
        <reference source="CESA" ref_id="CESA-2013:1269"/>
        <reference source="CVE" ref_id="CVE-2013-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1718.html"/>
        <reference source="CVE" ref_id="CVE-2013-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1722.html"/>
        <reference source="CVE" ref_id="CVE-2013-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1725.html"/>
        <reference source="CVE" ref_id="CVE-2013-1730" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1730.html"/>
        <reference source="CVE" ref_id="CVE-2013-1732" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1732.html"/>
        <reference source="CVE" ref_id="CVE-2013-1735" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1735.html"/>
        <reference source="CVE" ref_id="CVE-2013-1736" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1736.html"/>
        <reference source="CVE" ref_id="CVE-2013-1737" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1737.html"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:37.718-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:42.369-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:52.958-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:91569"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91610"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:91549"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.9-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92032"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20906" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1284: spice-gtk security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>spice-gtk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1284-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1284.html"/>
        <reference source="CESA" ref_id="CESA-2012:1284"/>
        <reference source="CVE" ref_id="CVE-2012-4425" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4425.html"/>
        <description>libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable.  NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse environment variables, not in libgio itself.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:47.258-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:21.502-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:37.289-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="spice-gtk-tools is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:93845"/>
          <criterion comment="spice-glib-devel is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:94703"/>
          <criterion comment="spice-glib is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:93981"/>
          <criterion comment="spice-gtk-python is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:94563"/>
          <criterion comment="spice-gtk is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:94595"/>
          <criterion comment="spice-gtk-devel is earlier than 0:0.11-11.el6_3.1" test_ref="oval:org.mitre.oval:tst:94649"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20905" version="59" class="patch">
      <metadata>
        <title>RHSA-2013:0737: subversion security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0737-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0737.html"/>
        <reference source="CESA" ref_id="CESA-2013:0737"/>
        <reference source="CVE" ref_id="CVE-2013-1845" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1845.html"/>
        <reference source="CVE" ref_id="CVE-2013-1846" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1846.html"/>
        <reference source="CVE" ref_id="CVE-2013-1847" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1847.html"/>
        <reference source="CVE" ref_id="CVE-2013-1849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1849.html"/>
        <description>The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:20.702-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:42.114-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:52.731-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:90885"/>
            <criterion comment="subversion-kde is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:91117"/>
            <criterion comment="subversion-svn2cl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:90860"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:90929"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:91148"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:91136"/>
            <criterion comment="subversion-gnome is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:90861"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:91126"/>
            <criterion comment="subversion is earlier than 0:1.6.11-9.el6_4" test_ref="oval:org.mitre.oval:tst:90671"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="subversion-ruby is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:90969"/>
            <criterion comment="subversion-devel is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:91040"/>
            <criterion comment="subversion-javahl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:90979"/>
            <criterion comment="mod_dav_svn is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:91130"/>
            <criterion comment="subversion-perl is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:91166"/>
            <criterion comment="subversion is earlier than 0:1.6.11-11.el5_9" test_ref="oval:org.mitre.oval:tst:90824"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20899" version="61" class="patch">
      <metadata>
        <title>RHSA-2013:1801: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1801-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1801.html"/>
        <reference source="CESA" ref_id="CESA-2013:1801"/>
        <reference source="CVE" ref_id="CVE-2013-2141" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2141.html"/>
        <reference source="CVE" ref_id="CVE-2013-4470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4470.html"/>
        <reference source="CVE" ref_id="CVE-2013-6367" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6367.html"/>
        <reference source="CVE" ref_id="CVE-2013-6368" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6368.html"/>
        <description>The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:31.523-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:41.948-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:52.520-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20899 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:39.089-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:17.357-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91721"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91941"/>
          <criterion comment="kernel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91865"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91873"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91646"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91077"/>
          <criterion comment="perf is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91059"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91481"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91806"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91918"/>
          <criterion comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91656"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:90991"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-431.1.2.el6" test_ref="oval:org.mitre.oval:tst:91349"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20895" version="409" class="patch">
      <metadata>
        <title>RHSA-2013:1451: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1451-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1451.html"/>
        <reference source="CESA" ref_id="CESA-2013:1451"/>
        <reference source="CVE" ref_id="CVE-2013-3829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3829.html"/>
        <reference source="CVE" ref_id="CVE-2013-4002" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4002.html"/>
        <reference source="CVE" ref_id="CVE-2013-5772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5784" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5784.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5800" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5800.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5820" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5820.html"/>
        <reference source="CVE" ref_id="CVE-2013-5823" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5823.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5838" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5838.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <reference source="CVE" ref_id="CVE-2013-5850" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5850.html"/>
        <reference source="CVE" ref_id="CVE-2013-5851" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5851.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to JAXP.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:12.728-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:40.690-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:51.404-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.45-2.4.3.2.el6_4" test_ref="oval:org.mitre.oval:tst:91682"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.45-2.4.3.2.el6_4" test_ref="oval:org.mitre.oval:tst:91795"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.45-2.4.3.2.el6_4" test_ref="oval:org.mitre.oval:tst:91496"/>
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.45-2.4.3.2.el6_4" test_ref="oval:org.mitre.oval:tst:91570"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.45-2.4.3.2.el6_4" test_ref="oval:org.mitre.oval:tst:91476"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20894" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0581: libxml2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0581-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0581.html"/>
        <reference source="CESA" ref_id="CESA-2013:0581"/>
        <reference source="CVE" ref_id="CVE-2013-0338" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0338.html"/>
        <description>libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entity expansion" with linear complexity.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:11.707-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:40.574-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:51.272-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:90765"/>
            <criterion comment="libxml2-python is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:90683"/>
            <criterion comment="libxml2 is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:90193"/>
            <criterion comment="libxml2-static is earlier than 0:2.7.6-12.el6_4.1" test_ref="oval:org.mitre.oval:tst:89794"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:90688"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:90256"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.21.el5_9.1" test_ref="oval:org.mitre.oval:tst:90374"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20885" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0504: dhcp security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0504-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0504.html"/>
        <reference source="CESA" ref_id="CESA-2013:0504"/>
        <reference source="CVE" ref_id="CVE-2012-3955" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3955.html"/>
        <description>ISC DHCP 4.1.x before 4.1-ESV-R7 and 4.2.x before 4.2.4-P2 allows remote attackers to cause a denial of service (daemon crash) in opportunistic circumstances by establishing an IPv6 lease in an environment where the lease expiration time is later reduced.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:42.720-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:39.663-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:50.216-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dhclient is earlier than 12:4.1.1-34.P1.el6" test_ref="oval:org.mitre.oval:tst:90202"/>
          <criterion comment="dhcp-devel is earlier than 12:4.1.1-34.P1.el6" test_ref="oval:org.mitre.oval:tst:90483"/>
          <criterion comment="dhcp is earlier than 12:4.1.1-34.P1.el6" test_ref="oval:org.mitre.oval:tst:90211"/>
          <criterion comment="dhcp-common is earlier than 12:4.1.1-34.P1.el6" test_ref="oval:org.mitre.oval:tst:90541"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20875" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0531: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0531-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0531.html"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <reference source="CVE" ref_id="CVE-2013-1487" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1487.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE 7 Update 13 and earlier and 6 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:06.616-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:39.205-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:49.724-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90113"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90571"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90601"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90277"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90232"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.41-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90694"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20874" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0830: kernel security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0830-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0830.html"/>
        <reference source="CESA" ref_id="CESA-2013:0830"/>
        <reference source="CVE" ref_id="CVE-2013-2094" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2094.html"/>
        <description>The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:25.308-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:39.062-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:49.554-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:91113"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:90703"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:91030"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:90305"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:91192"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:90681"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:90737"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:90879"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:91286"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:90896"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:91147"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.6.2.el6" test_ref="oval:org.mitre.oval:tst:91212"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20870" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0600: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0600-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0600.html"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:51.881-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:38.583-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:49.120-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90880"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90617"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90889"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90554"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90146"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.17-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90775"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20865" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0011: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0011-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0011.html"/>
        <reference source="CVE" ref_id="CVE-2011-2462" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2462.html"/>
        <reference source="CVE" ref_id="CVE-2011-4369" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4369.html"/>
        <description>Unspecified vulnerability in the PRC component in Adobe Reader and Acrobat 9.x before 9.4.7 on Windows, Adobe Reader and Acrobat 9.x through 9.4.6 on Mac OS X, Adobe Reader and Acrobat 10.x through 10.1.1 on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:36.399-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:20.809-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:36.329-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:92512"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.7-1.el5" test_ref="oval:org.mitre.oval:tst:92798"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="acroread is earlier than 0:9.4.7-1.el6" test_ref="oval:org.mitre.oval:tst:92254"/>
            <criterion comment="acroread-plugin is earlier than 0:9.4.7-1.el6" test_ref="oval:org.mitre.oval:tst:92782"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20861" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:1441: rubygems security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>rubygems</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1441-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1441.html"/>
        <reference source="CESA" ref_id="CESA-2013:1441"/>
        <reference source="CVE" ref_id="CVE-2012-2005" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2005.html"/>
        <reference source="CVE" ref_id="CVE-2012-2126" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2126.html"/>
        <reference source="CVE" ref_id="CVE-2013-4287" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4287.html"/>
        <description>Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:59.973-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:38.340-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:48.589-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="rubygems is earlier than 0:1.3.7-4.el6_4" test_ref="oval:org.mitre.oval:tst:91730"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20855" version="171" class="patch">
      <metadata>
        <title>RHSA-2013:0144: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0144-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0144.html"/>
        <reference source="CESA" ref_id="CESA-2013:0144"/>
        <reference source="CVE" ref_id="CVE-2013-0744" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0744.html"/>
        <reference source="CVE" ref_id="CVE-2013-0746" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0746.html"/>
        <reference source="CVE" ref_id="CVE-2013-0748" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0748.html"/>
        <reference source="CVE" ref_id="CVE-2013-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0750.html"/>
        <reference source="CVE" ref_id="CVE-2013-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0753.html"/>
        <reference source="CVE" ref_id="CVE-2013-0754" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0754.html"/>
        <reference source="CVE" ref_id="CVE-2013-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0758.html"/>
        <reference source="CVE" ref_id="CVE-2013-0759" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0759.html"/>
        <reference source="CVE" ref_id="CVE-2013-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0762.html"/>
        <reference source="CVE" ref_id="CVE-2013-0766" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0766.html"/>
        <reference source="CVE" ref_id="CVE-2013-0767" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0767.html"/>
        <reference source="CVE" ref_id="CVE-2013-0769" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0769.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:16.053-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:37.753-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:47.485-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:90361"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:90186"/>
            <criterion comment="firefox is earlier than 0:10.0.12-1.el6_3" test_ref="oval:org.mitre.oval:tst:90260"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91449"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92112"/>
            <criterion comment="firefox is earlier than 0:10.0.12-1.el6.centos" test_ref="oval:org.mitre.oval:tst:91642"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:90138"/>
            <criterion comment="xulrunner is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:90031"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.12-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91994"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.12-1.el5_9" test_ref="oval:org.mitre.oval:tst:89474"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20850" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:0223: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0223-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0223.html"/>
        <reference source="CESA" ref_id="CESA-2013:0223"/>
        <reference source="CVE" ref_id="CVE-2012-4398" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4398.html"/>
        <reference source="CVE" ref_id="CVE-2012-4461" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4461.html"/>
        <reference source="CVE" ref_id="CVE-2012-4530" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4530.html"/>
        <description>The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:58.658-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:37.113-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:46.857-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:90047"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:90498"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:89806"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:90404"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:90445"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:90329"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:90325"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:89963"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:90369"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:90197"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:90470"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.22.1.el6" test_ref="oval:org.mitre.oval:tst:90467"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20849" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0523: ccid security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ccid</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0523-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0523.html"/>
        <reference source="CESA" ref_id="CESA-2013:0523"/>
        <reference source="CVE" ref_id="CVE-2010-4530" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4530.html"/>
        <description>Signedness error in ccid_serial.c in libccid in the USB Chip/Smart Card Interface Devices (CCID) driver, as used in pcscd in PCSC-Lite 1.5.3 and possibly other products, allows physically proximate attackers to execute arbitrary code via a smart card with a crafted serial number that causes a negative value to be used in a memcpy operation, which triggers a buffer overflow.  NOTE: some sources refer to this issue as an integer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:04.599-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:37.004-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:46.640-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="ccid is earlier than 0:1.3.9-6.el6" test_ref="oval:org.mitre.oval:tst:90716"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20848" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1480: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1480-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1480.html"/>
        <reference source="CESA" ref_id="CESA-2013:1480"/>
        <reference source="CVE" ref_id="CVE-2013-5599" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5599.html"/>
        <description>Use-after-free vulnerability in the nsIPresShell::GetPresContext function in the PresShell (aka presentation shell) implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via vectors involving a CANVAS element, a mozTextStyle attribute, and an onresize event.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:43.231-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:36.852-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:46.415-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el6_4" test_ref="oval:org.mitre.oval:tst:91552"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92285"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el5_10" test_ref="oval:org.mitre.oval:tst:90990"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.10-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91844"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20847" version="87" class="patch">
      <metadata>
        <title>RHSA-2013:1173: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1173-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1173.html"/>
        <reference source="CESA" ref_id="CESA-2013:1173"/>
        <reference source="CVE" ref_id="CVE-2012-6544" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6544.html"/>
        <reference source="CVE" ref_id="CVE-2013-2146" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2146.html"/>
        <reference source="CVE" ref_id="CVE-2013-2206" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2206.html"/>
        <reference source="CVE" ref_id="CVE-2013-2224" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2224.html"/>
        <reference source="CVE" ref_id="CVE-2013-2232" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2232.html"/>
        <reference source="CVE" ref_id="CVE-2013-2237" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2237.html"/>
        <description>The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify_policy interface of an IPSec key_socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:38.458-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:36.652-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:45.854-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91469"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91660"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91466"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91378"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:90996"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91589"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91631"/>
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91365"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91564"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91067"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91491"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.18.1.el6" test_ref="oval:org.mitre.oval:tst:91464"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20845" version="55" class="patch">
      <metadata>
        <title>RHSA-2012:0080: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0080-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0080.html"/>
        <reference source="CESA" ref_id="CESA-2012:0080"/>
        <reference source="CVE" ref_id="CVE-2011-3659" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3659.html"/>
        <reference source="CVE" ref_id="CVE-2011-3670" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3670.html"/>
        <reference source="CVE" ref_id="CVE-2012-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0442.html"/>
        <reference source="CVE" ref_id="CVE-2012-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0449.html"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:35.551-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:20.544-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:35.971-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:3.1.18-1.el6_2" test_ref="oval:org.mitre.oval:tst:92416"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:3.1.18-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94857"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20843" version="68" class="patch">
      <metadata>
        <title>RHSA-2012:0128: httpd security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>httpd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0128-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0128.html"/>
        <reference source="CESA" ref_id="CESA-2012:0128"/>
        <reference source="CVE" ref_id="CVE-2011-3607" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3607.html"/>
        <reference source="CVE" ref_id="CVE-2011-3639" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3639.html"/>
        <reference source="CVE" ref_id="CVE-2011-4317" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4317.html"/>
        <reference source="CVE" ref_id="CVE-2012-0031" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0031.html"/>
        <reference source="CVE" ref_id="CVE-2012-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0053.html"/>
        <description>protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:04.127-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:20.352-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:35.731-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-15.el6_2.1" test_ref="oval:org.mitre.oval:tst:92889"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-15.el6_2.1" test_ref="oval:org.mitre.oval:tst:92962"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-15.el6_2.1" test_ref="oval:org.mitre.oval:tst:92860"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-15.el6_2.1" test_ref="oval:org.mitre.oval:tst:92903"/>
            <criterion comment="httpd is earlier than 0:2.2.15-15.el6_2.1" test_ref="oval:org.mitre.oval:tst:93023"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="httpd-devel is earlier than 0:2.2.15-15.el6.centos.1" test_ref="oval:org.mitre.oval:tst:94476"/>
            <criterion comment="httpd-tools is earlier than 0:2.2.15-15.el6.centos.1" test_ref="oval:org.mitre.oval:tst:95003"/>
            <criterion comment="httpd-manual is earlier than 0:2.2.15-15.el6.centos.1" test_ref="oval:org.mitre.oval:tst:94871"/>
            <criterion comment="mod_ssl is earlier than 0:2.2.15-15.el6.centos.1" test_ref="oval:org.mitre.oval:tst:94269"/>
            <criterion comment="httpd is earlier than 0:2.2.15-15.el6.centos.1" test_ref="oval:org.mitre.oval:tst:94998"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20842" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1120: haproxy security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>haproxy</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1120-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1120.html"/>
        <reference source="CESA" ref_id="CESA-2013:1120"/>
        <reference source="CVE" ref_id="CVE-2013-2175" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2175.html"/>
        <description>HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:37.250-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:36.578-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:45.703-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="haproxy is earlier than 0:1.4.22-5.el6_4" test_ref="oval:org.mitre.oval:tst:91523"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20836" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:0213: nss, nss-util, and nspr security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0213-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0213.html"/>
        <reference source="CESA" ref_id="CESA-2013:0213"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Netscape Portable Runtime (NSPR) provides platform
independence for non-GUI operating system facilities.

It was found that a Certificate Authority (CA) mis-issued two intermediate
certificates to customers. These certificates could be used to launch
man-in-the-middle attacks. This update renders those certificates as
untrusted. This covers all uses of the certificates, including SSL, S/MIME,
and code signing. (BZ#890605)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

In addition, the nss package has been upgraded to upstream version 3.13.6,
the nss-util package has been upgraded to upstream version 3.13.6, and the
nspr package has been upgraded to upstream version 4.9.2. These updates
provide a number of bug fixes and enhancements over the previous versions.
(BZ#891663, BZ#891670, BZ#891661)

Users of NSS, NSPR, and nss-util are advised to upgrade to these updated
packages, which fix these issues and add these enhancements. After
installing this update, applications using NSS, NSPR, or nss-util must be
restarted for this update to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:26.715-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:36.508-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:45.531-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20836 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:36.622-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:12.852-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nss-util is earlier than 0:3.13.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:90333"/>
          <criterion comment="nss-util-devel is earlier than 0:3.13.6-1.el6_3" test_ref="oval:org.mitre.oval:tst:90166"/>
          <criterion comment="nss-tools is earlier than 0:3.13.6-2.el6_3" test_ref="oval:org.mitre.oval:tst:90282"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.13.6-2.el6_3" test_ref="oval:org.mitre.oval:tst:90005"/>
          <criterion comment="nss-sysinit is earlier than 0:3.13.6-2.el6_3" test_ref="oval:org.mitre.oval:tst:90165"/>
          <criterion comment="nss is earlier than 0:3.13.6-2.el6_3" test_ref="oval:org.mitre.oval:tst:90303"/>
          <criterion comment="nss-devel is earlier than 0:3.13.6-2.el6_3" test_ref="oval:org.mitre.oval:tst:90340"/>
          <criterion comment="nspr is earlier than 0:4.9.2-0.el6_3.1" test_ref="oval:org.mitre.oval:tst:90474"/>
          <criterion comment="nspr-devel is earlier than 0:4.9.2-0.el6_3.1" test_ref="oval:org.mitre.oval:tst:90486"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20835" version="283" class="patch">
      <metadata>
        <title>RHSA-2013:0245: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0245-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0245.html"/>
        <reference source="CESA" ref_id="CESA-2013:0245"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0429.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0435.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0441.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.  NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:34.789-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:36.088-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:44.456-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:90136"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:89986"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:89892"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:90492"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.54.1.11.6.el6_3" test_ref="oval:org.mitre.oval:tst:89868"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20834" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0964: tomcat6 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0964-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0964.html"/>
        <reference source="CESA" ref_id="CESA-2013:0964"/>
        <reference source="CVE" ref_id="CVE-2013-2067" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2067.html"/>
        <description>java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:36.522-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:35.929-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:44.177-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:91140"/>
          <criterion comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:90894"/>
          <criterion comment="tomcat6 is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:91034"/>
          <criterion comment="tomcat6-docs-webapp is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:91009"/>
          <criterion comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:90845"/>
          <criterion comment="tomcat6-webapps is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:91359"/>
          <criterion comment="tomcat6-lib is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:91402"/>
          <criterion comment="tomcat6-admin-webapps is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:91444"/>
          <criterion comment="tomcat6-javadoc is earlier than 0:6.0.24-57.el6_4" test_ref="oval:org.mitre.oval:tst:91312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20827" version="143" class="patch">
      <metadata>
        <title>RHSA-2013:0982: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0982-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0982.html"/>
        <reference source="CESA" ref_id="CESA-2013:0982"/>
        <reference source="CVE" ref_id="CVE-2013-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1682.html"/>
        <reference source="CVE" ref_id="CVE-2013-1684" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1684.html"/>
        <reference source="CVE" ref_id="CVE-2013-1685" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1685.html"/>
        <reference source="CVE" ref_id="CVE-2013-1686" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1686.html"/>
        <reference source="CVE" ref_id="CVE-2013-1687" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1687.html"/>
        <reference source="CVE" ref_id="CVE-2013-1690" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1690.html"/>
        <reference source="CVE" ref_id="CVE-2013-1692" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1692.html"/>
        <reference source="CVE" ref_id="CVE-2013-1693" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1693.html"/>
        <reference source="CVE" ref_id="CVE-2013-1694" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1694.html"/>
        <reference source="CVE" ref_id="CVE-2013-1697" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1697.html"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:18.059-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:34.953-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:43.242-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:91506"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92088"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:91503"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:17.0.7-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92131"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20823" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:1413: thunderbird security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1413-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1413.html"/>
        <reference source="CESA" ref_id="CESA-2012:1413"/>
        <reference source="CVE" ref_id="CVE-2012-4194" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4194.html"/>
        <reference source="CVE" ref_id="CVE-2012-4195" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4195.html"/>
        <reference source="CVE" ref_id="CVE-2012-4196" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4196.html"/>
        <description>Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:00.926-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:20.137-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:35.485-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:93889"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94895"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:94753"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94808"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20822" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0165: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0165-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0165.html"/>
        <reference source="CESA" ref_id="CESA-2013:0165"/>
        <reference source="CVE" ref_id="CVE-2012-3174" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3174.html"/>
        <reference source="CVE" ref_id="CVE-2013-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0422.html"/>
        <description>Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114.  CVE-2013-0422 covers both the JMX/MBean and Reflection API issues.  NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks.  NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11.  If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:01.467-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:34.680-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:42.599-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:90037"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:90309"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:90111"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:90341"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.1.el6_3" test_ref="oval:org.mitre.oval:tst:90274"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:89635"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:90226"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:90353"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:90295"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.4.el5_9.1" test_ref="oval:org.mitre.oval:tst:89394"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20820" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1100: qemu-kvm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1100-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1100.html"/>
        <reference source="CESA" ref_id="CESA-2013:1100"/>
        <reference source="CVE" ref_id="CVE-2013-2231" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2231.html"/>
        <description>Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, and Workstation Supplementary 6, when installing on Windows, allows local users to gain privileges via a crafted program in an unspecified folder.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:22.958-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:34.465-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:42.225-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:91049"/>
            <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:91438"/>
            <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:91408"/>
            <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:91268"/>
            <criterion comment="qemu-guest-agent-win32 is earlier than 2:0.12.1.2-2.355.el6_4.6" test_ref="oval:org.mitre.oval:tst:91479"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.355.0.1.el6.centos.6" test_ref="oval:org.mitre.oval:tst:92122"/>
            <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.355.0.1.el6.centos.6" test_ref="oval:org.mitre.oval:tst:92135"/>
            <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.355.0.1.el6.centos.6" test_ref="oval:org.mitre.oval:tst:92203"/>
            <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.355.0.1.el6.centos.6" test_ref="oval:org.mitre.oval:tst:92232"/>
            <criterion comment="qemu-guest-agent-win32 is earlier than 2:0.12.1.2-2.355.0.1.el6.centos.6" test_ref="oval:org.mitre.oval:tst:92019"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20816" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1805: samba4 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba4</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1805-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1805.html"/>
        <reference source="CESA" ref_id="CESA-2013:1805"/>
        <reference source="CVE" ref_id="CVE-2013-4408" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4408.html"/>
        <description>Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before 4.1.3 allows remote AD domain controllers to execute arbitrary code via an invalid fragment length in a DCE-RPC packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:40.269-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:34.091-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:41.547-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91591"/>
          <criterion comment="samba4-dc-libs is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91343"/>
          <criterion comment="samba4-winbind-clients is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91006"/>
          <criterion comment="samba4-pidl is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91928"/>
          <criterion comment="samba4-swat is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91924"/>
          <criterion comment="samba4-libs is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91993"/>
          <criterion comment="samba4-test is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91757"/>
          <criterion comment="samba4-python is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91841"/>
          <criterion comment="samba4-common is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91838"/>
          <criterion comment="samba4-dc is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91167"/>
          <criterion comment="samba4 is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91351"/>
          <criterion comment="samba4-client is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91740"/>
          <criterion comment="samba4-winbind is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91751"/>
          <criterion comment="samba4-devel is earlier than 0:4.0.0-60.el6_5.rc4" test_ref="oval:org.mitre.oval:tst:91809"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20811" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0533: samba and samba3x security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>samba3x</product>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0533-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0533.html"/>
        <reference source="CESA" ref_id="CESA-2012:0533"/>
        <reference source="CVE" ref_id="CVE-2012-2111" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2111.html"/>
        <description>The (1) CreateAccount, (2) OpenAccount, (3) AddAccountRights, and (4) RemoveAccountRights LSA RPC procedures in smbd in Samba 3.4.x before 3.4.17, 3.5.x before 3.5.15, and 3.6.x before 3.6.5 do not properly restrict modifications to the privileges database, which allows remote authenticated users to obtain the "take ownership" privilege via an LSA connection.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:11.148-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:19.813-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:35.220-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba3x-doc is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93088"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93296"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93288"/>
            <criterion comment="samba3x is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93338"/>
            <criterion comment="samba3x-client is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93339"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:92936"/>
            <criterion comment="samba3x-swat is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93290"/>
            <criterion comment="samba3x-common is earlier than 0:3.5.10-0.109.el5_8" test_ref="oval:org.mitre.oval:tst:93391"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="samba-client is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:92947"/>
            <criterion comment="samba-domainjoin-gui is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93091"/>
            <criterion comment="samba is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:92968"/>
            <criterion comment="samba-common is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93188"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93314"/>
            <criterion comment="samba-doc is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93131"/>
            <criterion comment="samba-winbind is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:92423"/>
            <criterion comment="samba-winbind-devel is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:92876"/>
            <criterion comment="samba-winbind-clients is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93260"/>
            <criterion comment="samba-swat is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93280"/>
            <criterion comment="libsmbclient is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93080"/>
            <criterion comment="samba-winbind-krb5-locator is earlier than 0:3.5.10-116.el6_2" test_ref="oval:org.mitre.oval:tst:93144"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20807" version="353" class="patch">
      <metadata>
        <title>RHSA-2013:1014: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1014-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1014.html"/>
        <reference source="CESA" ref_id="CESA-2013:1014"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2445.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2461" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2461.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ByteBandedRaster size checks" in 2D.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:18.992-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:33.264-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:40.526-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:90750"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:90758"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:91390"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:91354"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.62.1.11.11.90.el6_4" test_ref="oval:org.mitre.oval:tst:90542"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:91120"/>
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:91352"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:91144"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:91474"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.41.1.11.11.90.el5_9" test_ref="oval:org.mitre.oval:tst:91008"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20806" version="61" class="patch">
      <metadata>
        <title>RHSA-2013:0643: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0643-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0643.html"/>
        <reference source="CVE" ref_id="CVE-2013-0646" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0646.html"/>
        <reference source="CVE" ref_id="CVE-2013-0650" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0650.html"/>
        <reference source="CVE" ref_id="CVE-2013-1371" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1371.html"/>
        <reference source="CVE" ref_id="CVE-2013-1375" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1375.html"/>
        <description>Heap-based buffer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux, before 11.1.111.44 on Android 2.x and 3.x, and before 11.1.115.48 on Android 4.x; Adobe AIR before 3.6.0.6090; Adobe AIR SDK before 3.6.0.6090; and Adobe AIR SDK &amp; Compiler before 3.6.0.6090 allows attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:44.766-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:33.071-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:40.295-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20806 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:20.190-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:21.608-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.275-2.el5" test_ref="oval:org.mitre.oval:tst:137654"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.275-2.el6" test_ref="oval:org.mitre.oval:tst:91012"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20805" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:1861: nss security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1861-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1861.html"/>
        <reference source="CESA" ref_id="CESA-2013:1861"/>
        <description>Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications.

It was found that a subordinate Certificate Authority (CA) mis-issued an
intermediate certificate, which could be used to conduct man-in-the-middle
attacks. This update renders that particular intermediate certificate as
untrusted. (BZ#1038894)

Note: This fix only applies to applications using the NSS Builtin Object
Token. It does not render the certificates untrusted for applications that
use the NSS library, but do not use the NSS Builtin Object Token.

All NSS users should upgrade to these updated packages, which correct this
issue. After installing the update, applications using NSS must be
restarted for the changes to take effect.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:01.921-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:32.899-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:40.166-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20805 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.815-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:11.174-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss-tools is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:91461"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:91781"/>
            <criterion comment="nss is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:91128"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-4.el5_10" test_ref="oval:org.mitre.oval:tst:92049"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="nss-tools is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:91927"/>
            <criterion comment="nss-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:91770"/>
            <criterion comment="nss-sysinit is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:91693"/>
            <criterion comment="nss is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:91621"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-3.el6_5" test_ref="oval:org.mitre.oval:tst:92107"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20802" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0753: icedtea-web security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>icedtea-web</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0753-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0753.html"/>
        <reference source="CESA" ref_id="CESA-2013:0753"/>
        <reference source="CVE" ref_id="CVE-2013-1926" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1926.html"/>
        <reference source="CVE" ref_id="CVE-2013-1927" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1927.html"/>
        <description>The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:36.855-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:32.680-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:39.870-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="icedtea-web-javadoc is earlier than 0:1.2.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:91233"/>
          <criterion comment="icedtea-web is earlier than 0:1.2.3-2.el6_4" test_ref="oval:org.mitre.oval:tst:91115"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20801" version="243" class="patch">
      <metadata>
        <title>RHSA-2013:0254: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0254-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0254.html"/>
        <reference source="CVE" ref_id="CVE-2013-0637" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0637.html"/>
        <reference source="CVE" ref_id="CVE-2013-0638" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0638.html"/>
        <reference source="CVE" ref_id="CVE-2013-0639" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0639.html"/>
        <reference source="CVE" ref_id="CVE-2013-0642" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0642.html"/>
        <reference source="CVE" ref_id="CVE-2013-0644" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0644.html"/>
        <reference source="CVE" ref_id="CVE-2013-0645" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0645.html"/>
        <reference source="CVE" ref_id="CVE-2013-0647" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0647.html"/>
        <reference source="CVE" ref_id="CVE-2013-0649" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0649.html"/>
        <reference source="CVE" ref_id="CVE-2013-1365" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1365.html"/>
        <reference source="CVE" ref_id="CVE-2013-1366" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1366.html"/>
        <reference source="CVE" ref_id="CVE-2013-1367" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1367.html"/>
        <reference source="CVE" ref_id="CVE-2013-1368" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1368.html"/>
        <reference source="CVE" ref_id="CVE-2013-1369" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1369.html"/>
        <reference source="CVE" ref_id="CVE-2013-1370" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1370.html"/>
        <reference source="CVE" ref_id="CVE-2013-1372" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1372.html"/>
        <reference source="CVE" ref_id="CVE-2013-1373" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1373.html"/>
        <reference source="CVE" ref_id="CVE-2013-1374" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1374.html"/>
        <description>Use-after-free vulnerability in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.1.115.47 on Android 4.x; Adobe AIR before 3.6.0.597; and Adobe AIR SDK before 3.6.0.599 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0644 and CVE-2013-0649.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:17.398-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:32.073-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:39.146-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20801 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:25.999-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:20.213-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.270-1.el5" test_ref="oval:org.mitre.oval:tst:137717"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.270-1.el6" test_ref="oval:org.mitre.oval:tst:90452"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20797" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0742: 389-ds-base security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0742-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0742.html"/>
        <reference source="CESA" ref_id="CESA-2013:0742"/>
        <reference source="CVE" ref_id="CVE-2013-1897" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1897.html"/>
        <description>The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configuration is set to rootdse and the BASE search scope is used, which allows remote attackers to obtain sensitive information outside of the rootDSE via a crafted LDAP search.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:50.961-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:31.835-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:39.001-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-14.el6_4" test_ref="oval:org.mitre.oval:tst:90334"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-14.el6_4" test_ref="oval:org.mitre.oval:tst:91119"/>
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-14.el6_4" test_ref="oval:org.mitre.oval:tst:91110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20796" version="7" class="patch">
      <metadata>
        <title>RHSA-2013:1402: Adobe Reader - notification of end of updates (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1402-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1402.html"/>
        <description>Adobe Reader allows users to view and print documents in Portable Document
Format (PDF). Adobe Reader 9 reached the end of its support cycle on June
26, 2013, and will not receive any more security updates. Future versions
of Adobe Acrobat Reader will not be available with Red Hat Enterprise
Linux.

The Adobe Reader packages in the Red Hat Network (RHN) channels will
continue to be available. Red Hat will continue to provide these packages
only as a courtesy to customers. Red Hat will not provide updates to the
Adobe Reader packages.

This update disables the Adobe Reader web browser plug-in, which is
available via the acroread-plugin package, to prevent the exploitation of
security issues without user interaction when a user visits a malicious web
page.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:55.059-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:31.759-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:38.922-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20796 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:42.040-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:10.912-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20796 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:24.781-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:19.898-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.5-2.el5_10" test_ref="oval:org.mitre.oval:tst:137735"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.5-2.el5_10" test_ref="oval:org.mitre.oval:tst:137827"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.5-1.el6_4.1" test_ref="oval:org.mitre.oval:tst:91576"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.5-1.el6_4.1" test_ref="oval:org.mitre.oval:tst:91582"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20792" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0407: libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0407-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0407.html"/>
        <reference source="CESA" ref_id="CESA-2012:0407"/>
        <reference source="CVE" ref_id="CVE-2011-3045" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3045.html"/>
        <description>Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:57.163-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:19.455-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:34.769-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:93039"/>
            <criterion comment="libpng is earlier than 2:1.2.10-16.el5_8" test_ref="oval:org.mitre.oval:tst:92498"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-static is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:92961"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:92515"/>
            <criterion comment="libpng is earlier than 2:1.2.48-1.el6_2" test_ref="oval:org.mitre.oval:tst:93147"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20791" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0216: freetype security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>freetype</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0216-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0216.html"/>
        <reference source="CESA" ref_id="CESA-2013:0216"/>
        <reference source="CVE" ref_id="CVE-2012-5669" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5669.html"/>
        <description>The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:11.113-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:31.545-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:38.706-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:90287"/>
            <criterion comment="freetype is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:89896"/>
            <criterion comment="freetype-devel is earlier than 0:2.3.11-14.el6_3.1" test_ref="oval:org.mitre.oval:tst:90219"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="freetype-demos is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:90390"/>
            <criterion comment="freetype is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:90453"/>
            <criterion comment="freetype-devel is earlier than 0:2.2.1-32.el5_9.1" test_ref="oval:org.mitre.oval:tst:90435"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20790" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:1102: pidgin security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>pidgin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1102-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1102.html"/>
        <reference source="CESA" ref_id="CESA-2012:1102"/>
        <reference source="CVE" ref_id="CVE-2012-1178" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1178.html"/>
        <reference source="CVE" ref_id="CVE-2012-2318" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2318.html"/>
        <reference source="CVE" ref_id="CVE-2012-3374" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3374.html"/>
        <description>Buffer overflow in markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.5 allows remote attackers to execute arbitrary code via a crafted inline image in a message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:40.665-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:19.276-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:34.527-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93823"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93921"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93384"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93887"/>
            <criterion comment="finch-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:94029"/>
            <criterion comment="finch is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:94150"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93705"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93357"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-11.el5.4" test_ref="oval:org.mitre.oval:tst:93791"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="pidgin-docs is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:93753"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:93997"/>
            <criterion comment="pidgin-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:94106"/>
            <criterion comment="libpurple is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:94033"/>
            <criterion comment="libpurple-perl is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:93253"/>
            <criterion comment="finch-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:93960"/>
            <criterion comment="finch is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:93208"/>
            <criterion comment="libpurple-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:94207"/>
            <criterion comment="pidgin-devel is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:94055"/>
            <criterion comment="pidgin is earlier than 0:2.7.9-5.el6.2" test_ref="oval:org.mitre.oval:tst:94011"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20787" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1101: virtio-win security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>virtio-win</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1101-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1101.html"/>
        <reference source="CVE" ref_id="CVE-2013-2231" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2231.html"/>
        <description>Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, and Workstation Supplementary 6, when installing on Windows, allows local users to gain privileges via a crafted program in an unspecified folder.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:24.931-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:31.451-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:38.593-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="virtio-win is earlier than 0:1.6.5-6.el6_4" test_ref="oval:org.mitre.oval:tst:91556"/>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20783" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1270: polkit security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>polkit</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1270-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1270.html"/>
        <reference source="CESA" ref_id="CESA-2013:1270"/>
        <reference source="CVE" ref_id="CVE-2013-4288" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4288.html"/>
        <description>Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:22.366-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:31.334-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:38.465-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="polkit-desktop-policy is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:90893"/>
          <criterion comment="polkit-devel is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:91542"/>
          <criterion comment="polkit is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:91068"/>
          <criterion comment="polkit-docs is earlier than 0:0.96-5.el6_4" test_ref="oval:org.mitre.oval:tst:91395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20778" version="59" class="patch">
      <metadata>
        <title>RHSA-2013:0275: java-1.7.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0275-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0275.html"/>
        <reference source="CESA" ref_id="CESA-2013:0275"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <reference source="CVE" ref_id="CVE-2013-1484" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1484.html"/>
        <reference source="CVE" ref_id="CVE-2013-1485" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1485.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:12.832-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:30.773-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:37.819-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:89753"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:90381"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:90359"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:90465"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.7.1.el6_3" test_ref="oval:org.mitre.oval:tst:90370"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:90518"/>
            <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:89984"/>
            <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:90356"/>
            <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:90162"/>
            <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.7.1.el5_9" test_ref="oval:org.mitre.oval:tst:89532"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20771" version="157" class="patch">
      <metadata>
        <title>RHSA-2013:0217: mingw32-libxml2 security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>mingw32-libxml2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0217-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0217.html"/>
        <reference source="CESA" ref_id="CESA-2013:0217"/>
        <reference source="CVE" ref_id="CVE-2010-4008" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4008.html"/>
        <reference source="CVE" ref_id="CVE-2010-4494" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4494.html"/>
        <reference source="CVE" ref_id="CVE-2011-0216" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0216.html"/>
        <reference source="CVE" ref_id="CVE-2011-1944" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1944.html"/>
        <reference source="CVE" ref_id="CVE-2011-2821" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2821.html"/>
        <reference source="CVE" ref_id="CVE-2011-2834" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2834.html"/>
        <reference source="CVE" ref_id="CVE-2011-3102" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3102.html"/>
        <reference source="CVE" ref_id="CVE-2011-3905" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3905.html"/>
        <reference source="CVE" ref_id="CVE-2011-3919" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3919.html"/>
        <reference source="CVE" ref_id="CVE-2012-0841" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0841.html"/>
        <reference source="CVE" ref_id="CVE-2012-5134" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5134.html"/>
        <description>Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.1271.91 and other products, allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted entities in an XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:03.615-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:29.512-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:36.497-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="mingw32-libxml2 is earlier than 0:2.7.6-6.el6_3" test_ref="oval:org.mitre.oval:tst:90293"/>
          <criterion comment="mingw32-libxml2-static is earlier than 0:2.7.6-6.el6_3" test_ref="oval:org.mitre.oval:tst:90209"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20768" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0588: gnutls security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0588-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0588.html"/>
        <reference source="CESA" ref_id="CESA-2013:0588"/>
        <reference source="CVE" ref_id="CVE-2013-1619" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1619.html"/>
        <description>The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:48.588-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:29.192-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:36.333-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gnutls is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:89803"/>
            <criterion comment="gnutls-devel is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90567"/>
            <criterion comment="gnutls-utils is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90402"/>
            <criterion comment="gnutls-guile is earlier than 0:2.8.5-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90730"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gnutls is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:90776"/>
            <criterion comment="gnutls-devel is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:90723"/>
            <criterion comment="gnutls-utils is earlier than 0:1.4.1-10.el5_9.1" test_ref="oval:org.mitre.oval:tst:90443"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20767" version="115" class="patch">
      <metadata>
        <title>RHSA-2013:1268: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1268-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1268.html"/>
        <reference source="CESA" ref_id="CESA-2013:1268"/>
        <reference source="CVE" ref_id="CVE-2013-1718" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1718.html"/>
        <reference source="CVE" ref_id="CVE-2013-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1722.html"/>
        <reference source="CVE" ref_id="CVE-2013-1725" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1725.html"/>
        <reference source="CVE" ref_id="CVE-2013-1730" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1730.html"/>
        <reference source="CVE" ref_id="CVE-2013-1732" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1732.html"/>
        <reference source="CVE" ref_id="CVE-2013-1735" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1735.html"/>
        <reference source="CVE" ref_id="CVE-2013-1736" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1736.html"/>
        <reference source="CVE" ref_id="CVE-2013-1737" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1737.html"/>
        <description>Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the "this" object during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:32.096-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:28.770-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:35.904-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:91019"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:91674"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el6_4" test_ref="oval:org.mitre.oval:tst:91081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92283"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92118"/>
            <criterion comment="firefox is earlier than 0:17.0.9-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92173"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:91516"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:91150"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.9-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92110"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.9-1.el5_9" test_ref="oval:org.mitre.oval:tst:91648"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20766" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0273: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0273-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0273.html"/>
        <reference source="CESA" ref_id="CESA-2013:0273"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <reference source="CVE" ref_id="CVE-2013-1486" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1486.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 13 and earlier, 6 Update 39 and earlier, and 5.0 Update 39 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:39.555-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:28.608-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:35.673-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:90423"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:90054"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:90494"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:90273"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.56.1.11.8.el6_3" test_ref="oval:org.mitre.oval:tst:90267"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20763" version="5" class="patch">
      <metadata>
        <title>RHSA-2013:0666: Oracle Java SE 6 - notification of end of public updates (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0666-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0666.html"/>
        <description>Oracle Java SE version 6 includes the Oracle Java Runtime Environment and
the Oracle Java Software Development Kit.

Oracle Java SE 6 will not receive updates after February 28, 2013. The
Oracle Java SE 6 packages on the Red Hat Enterprise Linux 5 and 6
Supplementary media and in Red Hat Network (RHN) channels will continue to
be available.

Red Hat will continue to provide these packages only as a courtesy to
customers. Red Hat will not provide updates to these packages after this
date.

Once customers update their system by installing the packages associated
with this advisory, the Oracle Java Web Plug-in will be disabled. As a
result, customers who rely on Java-based browser applets may need to
re-configure their browser to use one of the Java implementations listed
in the Solution section below.

All users of java-1.6.0-sun are advised to upgrade to these updated
packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:55.195-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:28.518-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:35.569-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20763 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:41.447-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:09.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:90768"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:90586"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:90685"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:90909"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:90310"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.43-1jpp.4.el6_4" test_ref="oval:org.mitre.oval:tst:90939"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20758" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:1459: nspluginwrapper security and bug fix update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>nspluginwrapper</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1459-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1459.html"/>
        <reference source="CESA" ref_id="CESA-2012:1459"/>
        <reference source="CVE" ref_id="CVE-2011-2486" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-2486.html"/>
        <description>nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:09.962-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:18.804-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:33.570-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="nspluginwrapper is earlier than 0:1.4.4-1.el6_3" test_ref="oval:org.mitre.oval:tst:94882"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20755" version="59" class="patch">
      <metadata>
        <title>RHSA-2013:0911: kernel security, bug fix, and enhancement update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0911-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0911.html"/>
        <reference source="CESA" ref_id="CESA-2013:0911"/>
        <reference source="CVE" ref_id="CVE-2013-1935" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1935.html"/>
        <reference source="CVE" ref_id="CVE-2013-1943" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1943.html"/>
        <reference source="CVE" ref_id="CVE-2013-2017" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2017.html"/>
        <reference source="CVE" ref_id="CVE-2013-2188" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2188.html"/>
        <description>A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain write permissions, which allows local users to cause a denial of service (system crash) by leveraging access to a filesystem that is mounted read-only.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:01.704-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:27.720-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:35.123-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:91357"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:91413"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:91274"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:90835"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:90420"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:91386"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:90528"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:90689"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:91011"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:91253"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:91045"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.11.1.el6" test_ref="oval:org.mitre.oval:tst:90903"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20752" version="353" class="patch">
      <metadata>
        <title>RHSA-2013:0758: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0758-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0758.html"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1491.html"/>
        <reference source="CVE" ref_id="CVE-2013-1518" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1518.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1540" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1540.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1558.html"/>
        <reference source="CVE" ref_id="CVE-2013-1563" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1563.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2394" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2394.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2418" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2418.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2422.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2432.html"/>
        <reference source="CVE" ref_id="CVE-2013-2433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2433.html"/>
        <reference source="CVE" ref_id="CVE-2013-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2435.html"/>
        <reference source="CVE" ref_id="CVE-2013-2439" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2439.html"/>
        <reference source="CVE" ref_id="CVE-2013-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2440.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:52.293-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:26.899-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:34.095-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:91254"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:90846"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:90838"/>
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:90869"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:91190"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.45-1jpp.1.el6" test_ref="oval:org.mitre.oval:tst:91151"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20749" version="117" class="patch">
      <metadata>
        <title>RHSA-2013:1812: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1812-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1812.html"/>
        <reference source="CESA" ref_id="CESA-2013:1812"/>
        <reference source="CVE" ref_id="CVE-2013-0772" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0772.html"/>
        <reference source="CVE" ref_id="CVE-2013-5609" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5609.html"/>
        <reference source="CVE" ref_id="CVE-2013-5612" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5612.html"/>
        <reference source="CVE" ref_id="CVE-2013-5613" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5613.html"/>
        <reference source="CVE" ref_id="CVE-2013-5614" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5614.html"/>
        <reference source="CVE" ref_id="CVE-2013-5616" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5616.html"/>
        <reference source="CVE" ref_id="CVE-2013-5618" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5618.html"/>
        <reference source="CVE" ref_id="CVE-2013-6671" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-6671.html"/>
        <description>The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:45.951-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:26.397-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:33.610-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20749 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:38.262-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:08.832-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.el5_10" test_ref="oval:org.mitre.oval:tst:91963"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:24.2.0-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91784"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="firefox is earlier than 0:24.2.0-1.el6_5" test_ref="oval:org.mitre.oval:tst:91755"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="firefox is earlier than 0:24.2.0-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92230"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20746" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0656: krb5 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>krb5</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0656-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0656.html"/>
        <reference source="CESA" ref_id="CESA-2013:0656"/>
        <reference source="CVE" ref_id="CVE-2012-1016" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1016.html"/>
        <reference source="CVE" ref_id="CVE-2013-1415" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1415.html"/>
        <description>The pkinit_check_kdc_pkid function in plugins/preauth/pkinit/pkinit_crypto_openssl.c in the PKINIT implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.4 and 1.11.x before 1.11.1 does not properly handle errors during extraction of fields from an X.509 certificate, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed KRB5_PADATA_PK_AS_REQ AS-REQ request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:56.532-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:26.226-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:33.405-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="krb5-devel is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90799"/>
          <criterion comment="krb5-server-ldap is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90841"/>
          <criterion comment="krb5-workstation is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90545"/>
          <criterion comment="krb5-libs is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90053"/>
          <criterion comment="krb5-pkinit-openssl is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:91015"/>
          <criterion comment="krb5-server is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90800"/>
          <criterion comment="krb5 is earlier than 0:1.10.3-10.el6_4.1" test_ref="oval:org.mitre.oval:tst:90895"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20744" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0602: java-1.7.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.7.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0602-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0602.html"/>
        <reference source="CESA" ref_id="CESA-2013:0602"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:14.129-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:26.023-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:33.204-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.8.0.el6_4" test_ref="oval:org.mitre.oval:tst:90697"/>
          <criterion comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.8.0.el6_4" test_ref="oval:org.mitre.oval:tst:90725"/>
          <criterion comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.8.0.el6_4" test_ref="oval:org.mitre.oval:tst:90713"/>
          <criterion comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.8.0.el6_4" test_ref="oval:org.mitre.oval:tst:90580"/>
          <criterion comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.8.0.el6_4" test_ref="oval:org.mitre.oval:tst:90738"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20743" version="535" class="patch">
      <metadata>
        <title>RHSA-2013:0963: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0963-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0963.html"/>
        <reference source="CVE" ref_id="CVE-2013-1500" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1500.html"/>
        <reference source="CVE" ref_id="CVE-2013-1571" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1571.html"/>
        <reference source="CVE" ref_id="CVE-2013-2400" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2400.html"/>
        <reference source="CVE" ref_id="CVE-2013-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2407.html"/>
        <reference source="CVE" ref_id="CVE-2013-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2412.html"/>
        <reference source="CVE" ref_id="CVE-2013-2437" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2437.html"/>
        <reference source="CVE" ref_id="CVE-2013-2442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2442.html"/>
        <reference source="CVE" ref_id="CVE-2013-2443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2443.html"/>
        <reference source="CVE" ref_id="CVE-2013-2444" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2444.html"/>
        <reference source="CVE" ref_id="CVE-2013-2445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2445.html"/>
        <reference source="CVE" ref_id="CVE-2013-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2446.html"/>
        <reference source="CVE" ref_id="CVE-2013-2447" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2447.html"/>
        <reference source="CVE" ref_id="CVE-2013-2448" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2448.html"/>
        <reference source="CVE" ref_id="CVE-2013-2449" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2449.html"/>
        <reference source="CVE" ref_id="CVE-2013-2450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2450.html"/>
        <reference source="CVE" ref_id="CVE-2013-2451" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2451.html"/>
        <reference source="CVE" ref_id="CVE-2013-2452" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2452.html"/>
        <reference source="CVE" ref_id="CVE-2013-2453" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2453.html"/>
        <reference source="CVE" ref_id="CVE-2013-2454" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2454.html"/>
        <reference source="CVE" ref_id="CVE-2013-2455" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2455.html"/>
        <reference source="CVE" ref_id="CVE-2013-2456" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2456.html"/>
        <reference source="CVE" ref_id="CVE-2013-2457" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2457.html"/>
        <reference source="CVE" ref_id="CVE-2013-2458" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2458.html"/>
        <reference source="CVE" ref_id="CVE-2013-2459" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2459.html"/>
        <reference source="CVE" ref_id="CVE-2013-2460" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2460.html"/>
        <reference source="CVE" ref_id="CVE-2013-2461" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2461.html"/>
        <reference source="CVE" ref_id="CVE-2013-2462" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2462.html"/>
        <reference source="CVE" ref_id="CVE-2013-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2463.html"/>
        <reference source="CVE" ref_id="CVE-2013-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2464.html"/>
        <reference source="CVE" ref_id="CVE-2013-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2465.html"/>
        <reference source="CVE" ref_id="CVE-2013-2466" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2466.html"/>
        <reference source="CVE" ref_id="CVE-2013-2468" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2468.html"/>
        <reference source="CVE" ref_id="CVE-2013-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2469.html"/>
        <reference source="CVE" ref_id="CVE-2013-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2470.html"/>
        <reference source="CVE" ref_id="CVE-2013-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2471.html"/>
        <reference source="CVE" ref_id="CVE-2013-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2472.html"/>
        <reference source="CVE" ref_id="CVE-2013-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2473.html"/>
        <reference source="CVE" ref_id="CVE-2013-3744" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3744.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2400.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:48.929-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:24.677-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:31.863-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91435"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91363"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91471"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91196"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91397"/>
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.25-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91463"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20742" version="81" class="patch">
      <metadata>
        <title>RHSA-2012:0062: t1lib security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>t1lib</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0062-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0062.html"/>
        <reference source="CESA" ref_id="CESA-2012:0062"/>
        <reference source="CVE" ref_id="CVE-2010-2642" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2642.html"/>
        <reference source="CVE" ref_id="CVE-2011-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0433.html"/>
        <reference source="CVE" ref_id="CVE-2011-0764" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0764.html"/>
        <reference source="CVE" ref_id="CVE-2011-1552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1552.html"/>
        <reference source="CVE" ref_id="CVE-2011-1553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1553.html"/>
        <reference source="CVE" ref_id="CVE-2011-1554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1554.html"/>
        <description>Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:53.466-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:18.183-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:32.662-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="t1lib is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:91879"/>
          <criterion comment="t1lib-apps is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:92818"/>
          <criterion comment="t1lib-devel is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:92215"/>
          <criterion comment="t1lib-static is earlier than 0:5.1.2-6.el6_2.1" test_ref="oval:org.mitre.oval:tst:92182"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20740" version="369" class="patch">
      <metadata>
        <title>RHSA-2013:0826: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0826-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0826.html"/>
        <reference source="CVE" ref_id="CVE-2013-2549" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2549.html"/>
        <reference source="CVE" ref_id="CVE-2013-2718" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2718.html"/>
        <reference source="CVE" ref_id="CVE-2013-2719" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2719.html"/>
        <reference source="CVE" ref_id="CVE-2013-2720" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2720.html"/>
        <reference source="CVE" ref_id="CVE-2013-2721" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2721.html"/>
        <reference source="CVE" ref_id="CVE-2013-2722" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2722.html"/>
        <reference source="CVE" ref_id="CVE-2013-2723" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2723.html"/>
        <reference source="CVE" ref_id="CVE-2013-2724" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2724.html"/>
        <reference source="CVE" ref_id="CVE-2013-2725" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2725.html"/>
        <reference source="CVE" ref_id="CVE-2013-2726" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2726.html"/>
        <reference source="CVE" ref_id="CVE-2013-2727" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2727.html"/>
        <reference source="CVE" ref_id="CVE-2013-2729" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2729.html"/>
        <reference source="CVE" ref_id="CVE-2013-2730" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2730.html"/>
        <reference source="CVE" ref_id="CVE-2013-2731" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2731.html"/>
        <reference source="CVE" ref_id="CVE-2013-2732" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2732.html"/>
        <reference source="CVE" ref_id="CVE-2013-2733" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2733.html"/>
        <reference source="CVE" ref_id="CVE-2013-2734" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2734.html"/>
        <reference source="CVE" ref_id="CVE-2013-2735" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2735.html"/>
        <reference source="CVE" ref_id="CVE-2013-2736" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2736.html"/>
        <reference source="CVE" ref_id="CVE-2013-2737" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2737.html"/>
        <reference source="CVE" ref_id="CVE-2013-3337" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3337.html"/>
        <reference source="CVE" ref_id="CVE-2013-3338" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3338.html"/>
        <reference source="CVE" ref_id="CVE-2013-3339" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3339.html"/>
        <reference source="CVE" ref_id="CVE-2013-3340" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3340.html"/>
        <reference source="CVE" ref_id="CVE-2013-3341" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3341.html"/>
        <reference source="CVE" ref_id="CVE-2013-3346" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-3346.html"/>
        <description>Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:18.777-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:23.747-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:30.842-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20740 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:32.055-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:17.794-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:137039"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.5-1.el5_9" test_ref="oval:org.mitre.oval:tst:137850"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:90995"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.5-1.el6_4" test_ref="oval:org.mitre.oval:tst:91164"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20737" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0528: ipa security, bug fix and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ipa</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0528-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0528.html"/>
        <reference source="CESA" ref_id="CESA-2013:0528"/>
        <reference source="CVE" ref_id="CVE-2012-4546" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4546.html"/>
        <description>The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not properly update another Identity Management replica, which causes inconsistent Certificate Revocation Lists (CRLs) to be used and might allow remote attackers to bypass intended access restrictions via a revoked certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:31.150-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:23.452-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:30.480-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ipa-server-trust-ad is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:90711"/>
          <criterion comment="ipa-python is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:90431"/>
          <criterion comment="ipa-admintools is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:90450"/>
          <criterion comment="ipa-client is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:90105"/>
          <criterion comment="ipa-server-selinux is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:90460"/>
          <criterion comment="ipa-server is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:89737"/>
          <criterion comment="ipa is earlier than 0:3.0.0-25.el6" test_ref="oval:org.mitre.oval:tst:90510"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20735" version="73" class="patch">
      <metadata>
        <title>RHSA-2013:0169: vino security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>vino</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0169-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0169.html"/>
        <reference source="CESA" ref_id="CESA-2013:0169"/>
        <reference source="CVE" ref_id="CVE-2011-0904" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0904.html"/>
        <reference source="CVE" ref_id="CVE-2011-0905" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0905.html"/>
        <reference source="CVE" ref_id="CVE-2011-1164" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1164.html"/>
        <reference source="CVE" ref_id="CVE-2011-1165" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1165.html"/>
        <reference source="CVE" ref_id="CVE-2012-4429" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4429.html"/>
        <description>Vino 2.28, 2.32, 3.4.2, and earlier allows remote attackers to read clipboard activity by listening on TCP port 5900.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:35.775-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:23.211-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:30.253-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="vino is earlier than 0:2.28.1-8.el6_3" test_ref="oval:org.mitre.oval:tst:89490"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20729" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0630: kernel security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0630-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0630.html"/>
        <reference source="CESA" ref_id="CESA-2013:0630"/>
        <reference source="CVE" ref_id="CVE-2013-0228" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0228.html"/>
        <reference source="CVE" ref_id="CVE-2013-0268" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0268.html"/>
        <description>The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:43.863-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:22.855-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:29.797-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90280"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90593"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90797"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90927"/>
          <criterion comment="perf is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90598"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90854"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90051"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90975"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90866"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90878"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90067"/>
          <criterion comment="kernel is earlier than 0:2.6.32-358.2.1.el6" test_ref="oval:org.mitre.oval:tst:90728"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20726" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0505: squid security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>squid</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0505-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0505.html"/>
        <reference source="CESA" ref_id="CESA-2013:0505"/>
        <reference source="CVE" ref_id="CVE-2012-5643" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5643.html"/>
        <description>Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:54.674-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:22.738-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:29.660-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="squid is earlier than 7:3.1.10-16.el6" test_ref="oval:org.mitre.oval:tst:90605"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20724" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0215: abrt and libreport security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>abrt</product>
          <product>libreport</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0215-03" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0215.html"/>
        <reference source="CESA" ref_id="CESA-2013:0215"/>
        <reference source="CVE" ref_id="CVE-2012-5659" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5659.html"/>
        <reference source="CVE" ref_id="CVE-2012-5660" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5660.html"/>
        <description>abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:58.592-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:22.461-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:29.378-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libreport-plugin-rhtsupport is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90332"/>
            <criterion comment="libreport-plugin-mailx is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90179"/>
            <criterion comment="libreport-gtk-devel is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90141"/>
            <criterion comment="libreport-python is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90200"/>
            <criterion comment="libreport-cli is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90224"/>
            <criterion comment="libreport is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90422"/>
            <criterion comment="libreport-newt is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90377"/>
            <criterion comment="libreport-plugin-reportuploader is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90027"/>
            <criterion comment="libreport-gtk is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90307"/>
            <criterion comment="libreport-plugin-kerneloops is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90291"/>
            <criterion comment="libreport-devel is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90488"/>
            <criterion comment="libreport-plugin-logger is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90380"/>
            <criterion comment="libreport-plugin-bugzilla is earlier than 0:2.0.9-5.el6_3.2" test_ref="oval:org.mitre.oval:tst:90444"/>
            <criterion comment="abrt-desktop is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:89997"/>
            <criterion comment="abrt-gui is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:89906"/>
            <criterion comment="abrt is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:90403"/>
            <criterion comment="abrt-devel is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:90434"/>
            <criterion comment="abrt-addon-kerneloops is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:90366"/>
            <criterion comment="abrt-addon-vmcore is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:90449"/>
            <criterion comment="abrt-tui is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:90058"/>
            <criterion comment="abrt-addon-python is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:89754"/>
            <criterion comment="abrt-addon-ccpp is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:90418"/>
            <criterion comment="abrt-libs is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:90475"/>
            <criterion comment="abrt-cli is earlier than 0:2.0.8-6.el6_3.2" test_ref="oval:org.mitre.oval:tst:90459"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libreport-plugin-rhtsupport is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91835"/>
            <criterion comment="libreport-plugin-mailx is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91992"/>
            <criterion comment="libreport-gtk-devel is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91525"/>
            <criterion comment="libreport-python is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92108"/>
            <criterion comment="libreport-cli is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91867"/>
            <criterion comment="libreport is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92083"/>
            <criterion comment="libreport-newt is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92095"/>
            <criterion comment="libreport-plugin-reportuploader is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91441"/>
            <criterion comment="libreport-gtk is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92199"/>
            <criterion comment="libreport-plugin-kerneloops is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92179"/>
            <criterion comment="libreport-devel is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91638"/>
            <criterion comment="libreport-plugin-logger is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92210"/>
            <criterion comment="libreport-plugin-bugzilla is earlier than 0:2.0.9-5.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91988"/>
            <criterion comment="abrt-desktop is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92145"/>
            <criterion comment="abrt-gui is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92223"/>
            <criterion comment="abrt is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91604"/>
            <criterion comment="abrt-devel is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91718"/>
            <criterion comment="abrt-addon-kerneloops is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91953"/>
            <criterion comment="abrt-addon-vmcore is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91869"/>
            <criterion comment="abrt-tui is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92036"/>
            <criterion comment="abrt-addon-python is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92015"/>
            <criterion comment="abrt-addon-ccpp is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:91888"/>
            <criterion comment="abrt-libs is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92085"/>
            <criterion comment="abrt-cli is earlier than 0:2.0.8-6.el6.centos.2" test_ref="oval:org.mitre.oval:tst:92081"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20722" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0218: xorg-x11-drv-qxl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>xorg-x11-drv-qxl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0218-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0218.html"/>
        <reference source="CESA" ref_id="CESA-2013:0218"/>
        <reference source="CVE" ref_id="CVE-2013-0241" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0241.html"/>
        <description>The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex mutex.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:25.651-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:22.267-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:29.136-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="xorg-x11-drv-qxl is earlier than 0:0.0.14-14.el6_3" test_ref="oval:org.mitre.oval:tst:89503"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20721" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0663: sssd security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>sssd</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0663-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0663.html"/>
        <reference source="CESA" ref_id="CESA-2013:0663"/>
        <reference source="CVE" ref_id="CVE-2013-0287" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0287.html"/>
        <description>The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:35.486-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:22.120-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:28.967-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="sssd-client is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:90088"/>
          <criterion comment="libipa_hbac-python is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:91001"/>
          <criterion comment="libsss_sudo is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:90980"/>
          <criterion comment="sssd is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:90928"/>
          <criterion comment="libipa_hbac is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:90505"/>
          <criterion comment="libsss_idmap is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:90809"/>
          <criterion comment="libsss_autofs is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:90890"/>
          <criterion comment="libipa_hbac-devel is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:90966"/>
          <criterion comment="sssd-tools is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:90557"/>
          <criterion comment="libsss_idmap-devel is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:90864"/>
          <criterion comment="libsss_sudo-devel is earlier than 0:1.9.2-82.4.el6_4" test_ref="oval:org.mitre.oval:tst:90637"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20719" version="68" class="patch">
      <metadata>
        <title>RHSA-2012:0079: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0079-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0079.html"/>
        <reference source="CESA" ref_id="CESA-2012:0079"/>
        <reference source="CVE" ref_id="CVE-2011-3659" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3659.html"/>
        <reference source="CVE" ref_id="CVE-2011-3670" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3670.html"/>
        <reference source="CVE" ref_id="CVE-2012-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0442.html"/>
        <reference source="CVE" ref_id="CVE-2012-0444" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0444.html"/>
        <reference source="CVE" ref_id="CVE-2012-0449" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0449.html"/>
        <description>Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:16.263-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:17.857-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:32.218-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:92809"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:92255"/>
            <criterion comment="firefox is earlier than 0:3.6.26-1.el6_2" test_ref="oval:org.mitre.oval:tst:92852"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94231"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94932"/>
            <criterion comment="firefox is earlier than 0:3.6.26-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94032"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:1.9.2.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:92621"/>
            <criterion comment="xulrunner is earlier than 0:1.9.2.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:92651"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:3.6.26-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94504"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:3.6.26-1.el5_7" test_ref="oval:org.mitre.oval:tst:92761"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20714" version="33" class="patch">
      <metadata>
        <title>RHSA-2013:1518: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1518-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1518.html"/>
        <reference source="CVE" ref_id="CVE-2013-5329" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5329.html"/>
        <reference source="CVE" ref_id="CVE-2013-5330" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5330.html"/>
        <description>Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK &amp; Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:15.054-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:22.008-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:28.780-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20714 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:05.143-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:17.372-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.327-1.el5" test_ref="oval:org.mitre.oval:tst:137635"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.327-1.el6" test_ref="oval:org.mitre.oval:tst:91385"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20711" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0609: qemu-kvm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0609-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0609.html"/>
        <reference source="CESA" ref_id="CESA-2013:0609"/>
        <reference source="CVE" ref_id="CVE-2012-6075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6075.html"/>
        <description>Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:07.518-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:21.211-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:28.031-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qemu-guest-agent-win32 is earlier than 2:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:90785"/>
          <criterion comment="qemu-kvm is earlier than 2:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:90621"/>
          <criterion comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:90813"/>
          <criterion comment="qemu-img is earlier than 2:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:90921"/>
          <criterion comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.355.el6_4.2" test_ref="oval:org.mitre.oval:tst:90441"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20704" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0523: libpng security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0523-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0523.html"/>
        <reference source="CESA" ref_id="CESA-2012:0523"/>
        <reference source="CVE" ref_id="CVE-2011-3048" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3048.html"/>
        <description>The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted text chunk in a PNG image file, which triggers a memory allocation failure that is not properly handled, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:39.789-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:17.700-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:31.982-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-devel is earlier than 2:1.2.10-17.el5_8" test_ref="oval:org.mitre.oval:tst:92895"/>
            <criterion comment="libpng is earlier than 2:1.2.10-17.el5_8" test_ref="oval:org.mitre.oval:tst:93394"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libpng-static is earlier than 2:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:93233"/>
            <criterion comment="libpng-devel is earlier than 2:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:93402"/>
            <criterion comment="libpng is earlier than 2:1.2.49-1.el6_2" test_ref="oval:org.mitre.oval:tst:93355"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20699" version="68" class="patch">
      <metadata>
        <title>RHSA-2012:1580: kernel security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1580-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1580.html"/>
        <reference source="CESA" ref_id="CESA-2012:1580"/>
        <reference source="CVE" ref_id="CVE-2012-2100" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2100.html"/>
        <reference source="CVE" ref_id="CVE-2012-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2375.html"/>
        <reference source="CVE" ref_id="CVE-2012-4444" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4444.html"/>
        <reference source="CVE" ref_id="CVE-2012-4565" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4565.html"/>
        <reference source="CVE" ref_id="CVE-2012-5517" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5517.html"/>
        <description>The online_pages function in mm/memory_hotplug.c in the Linux kernel before 3.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact in opportunistic circumstances by using memory that was hot-added by an administrator.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:41.768-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:17.393-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:31.525-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94714"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94618"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94638"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94922"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94056"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94676"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94845"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94690"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94633"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94770"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94396"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.19.1.el6" test_ref="oval:org.mitre.oval:tst:94838"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20692" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0521: pam security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>pam</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0521-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0521.html"/>
        <reference source="CESA" ref_id="CESA-2013:0521"/>
        <reference source="CVE" ref_id="CVE-2011-3148" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3148.html"/>
        <reference source="CVE" ref_id="CVE-2011-3149" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3149.html"/>
        <description>The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows local users to cause a denial of service (CPU consumption).</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:02.652-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:21.079-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:27.872-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pam-devel is earlier than 0:1.1.1-13.el6" test_ref="oval:org.mitre.oval:tst:90642"/>
          <criterion comment="pam is earlier than 0:1.1.1-13.el6" test_ref="oval:org.mitre.oval:tst:89930"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20691" version="143" class="patch">
      <metadata>
        <title>RHSA-2013:0981: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0981-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0981.html"/>
        <reference source="CESA" ref_id="CESA-2013:0981"/>
        <reference source="CVE" ref_id="CVE-2013-1682" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1682.html"/>
        <reference source="CVE" ref_id="CVE-2013-1684" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1684.html"/>
        <reference source="CVE" ref_id="CVE-2013-1685" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1685.html"/>
        <reference source="CVE" ref_id="CVE-2013-1686" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1686.html"/>
        <reference source="CVE" ref_id="CVE-2013-1687" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1687.html"/>
        <reference source="CVE" ref_id="CVE-2013-1690" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1690.html"/>
        <reference source="CVE" ref_id="CVE-2013-1692" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1692.html"/>
        <reference source="CVE" ref_id="CVE-2013-1693" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1693.html"/>
        <reference source="CVE" ref_id="CVE-2013-1694" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1694.html"/>
        <reference source="CVE" ref_id="CVE-2013-1697" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1697.html"/>
        <description>The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:59:07.260-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:20.693-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:27.341-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:90913"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:91242"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el6_4" test_ref="oval:org.mitre.oval:tst:91355"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92100"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92264"/>
            <criterion comment="firefox is earlier than 0:17.0.7-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92047"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:91488"/>
            <criterion comment="xulrunner is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:91443"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.7-1.el5.centos" test_ref="oval:org.mitre.oval:tst:91490"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.7-1.el5_9" test_ref="oval:org.mitre.oval:tst:91455"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20690" version="45" class="patch">
      <metadata>
        <title>RHSA-2013:1459: gnupg2 security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>gnupg2</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1459-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1459.html"/>
        <reference source="CESA" ref_id="CESA-2013:1459"/>
        <reference source="CVE" ref_id="CVE-2012-6085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6085.html"/>
        <reference source="CVE" ref_id="CVE-2013-4351" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4351.html"/>
        <reference source="CVE" ref_id="CVE-2013-4402" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4402.html"/>
        <description>The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:16.780-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:20.531-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:27.129-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="gnupg2 is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:91783"/>
            <criterion comment="gnupg2-smime is earlier than 0:2.0.14-6.el6_4" test_ref="oval:org.mitre.oval:tst:91724"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criterion comment="gnupg2 is earlier than 0:2.0.10-6.el5_10" test_ref="oval:org.mitre.oval:tst:91826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20689" version="42" class="patch">
      <metadata>
        <title>RHSA-2012:1407: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1407-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1407.html"/>
        <reference source="CESA" ref_id="CESA-2012:1407"/>
        <reference source="CVE" ref_id="CVE-2012-4194" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4194.html"/>
        <reference source="CVE" ref_id="CVE-2012-4195" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4195.html"/>
        <reference source="CVE" ref_id="CVE-2012-4196" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4196.html"/>
        <description>Mozilla Firefox before 16.0.2, Firefox ESR 10.x before 10.0.10, Thunderbird before 16.0.2, Thunderbird ESR 10.x before 10.0.10, and SeaMonkey before 2.13.2 allow remote attackers to bypass the Same Origin Policy and read the Location object via a prototype property-injection attack that defeats certain protection mechanisms for this object.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:52.539-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:17.225-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:31.318-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:94479"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:94572"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:10.0.10-1.el5.centos" test_ref="oval:org.mitre.oval:tst:94825"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:10.0.10-1.el5_8" test_ref="oval:org.mitre.oval:tst:94822"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:94792"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:94695"/>
            <criterion comment="firefox is earlier than 0:10.0.10-1.el6_3" test_ref="oval:org.mitre.oval:tst:94827"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner-devel is earlier than 0:10.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94926"/>
            <criterion comment="xulrunner is earlier than 0:10.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:95064"/>
            <criterion comment="firefox is earlier than 0:10.0.10-1.el6.centos" test_ref="oval:org.mitre.oval:tst:94937"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20665" version="94" class="patch">
      <metadata>
        <title>RHSA-2012:1255: libexif security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>libexif</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1255-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1255.html"/>
        <reference source="CESA" ref_id="CESA-2012:1255"/>
        <reference source="CVE" ref_id="CVE-2012-2812" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2812.html"/>
        <reference source="CVE" ref_id="CVE-2012-2813" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2813.html"/>
        <reference source="CVE" ref_id="CVE-2012-2814" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2814.html"/>
        <reference source="CVE" ref_id="CVE-2012-2836" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2836.html"/>
        <reference source="CVE" ref_id="CVE-2012-2837" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2837.html"/>
        <reference source="CVE" ref_id="CVE-2012-2840" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2840.html"/>
        <reference source="CVE" ref_id="CVE-2012-2841" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2841.html"/>
        <description>Integer underflow in the exif_entry_get_value function in exif-entry.c in the EXIF Tag Parsing Library (aka libexif) 0.6.20 might allow remote attackers to execute arbitrary code via vectors involving a crafted buffer-size parameter during the formatting of an EXIF tag, leading to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:27.463-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:16.617-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:30.624-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libexif-devel is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:94462"/>
            <criterion comment="libexif is earlier than 0:0.6.21-1.el5_8" test_ref="oval:org.mitre.oval:tst:94215"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libexif-devel is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:94469"/>
            <criterion comment="libexif is earlier than 0:0.6.21-5.el6_3" test_ref="oval:org.mitre.oval:tst:94356"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20661" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0880: qt security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>qt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0880-04" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0880.html"/>
        <reference source="CESA" ref_id="CESA-2012:0880"/>
        <reference source="CVE" ref_id="CVE-2010-5076" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-5076.html"/>
        <reference source="CVE" ref_id="CVE-2011-3922" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-3922.html"/>
        <description>Stack-based buffer overflow in Google Chrome before 16.0.912.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to glyph handling.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:06.297-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:16.489-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:30.471-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="qt-odbc is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93914"/>
          <criterion comment="qt-demos is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93607"/>
          <criterion comment="qt-mysql is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93621"/>
          <criterion comment="qt-x11 is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93779"/>
          <criterion comment="qt-doc is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93941"/>
          <criterion comment="phonon-backend-gstreamer is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93874"/>
          <criterion comment="qt-sqlite is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93968"/>
          <criterion comment="qt-postgresql is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93979"/>
          <criterion comment="qt is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93966"/>
          <criterion comment="qt-examples is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93798"/>
          <criterion comment="qt-devel is earlier than 1:4.6.2-24.el6" test_ref="oval:org.mitre.oval:tst:93526"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20658" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1156: kernel security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>kernel</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1156-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1156.html"/>
        <reference source="CESA" ref_id="CESA-2012:1156"/>
        <reference source="CVE" ref_id="CVE-2011-1078" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1078.html"/>
        <reference source="CVE" ref_id="CVE-2012-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2383.html"/>
        <description>Integer overflow in the i915_gem_execbuffer2 function in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.3.5 on 32-bit platforms allows local users to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted ioctl call.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:12.051-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:16.355-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:30.317-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="kernel-kdump-devel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:94357"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:94111"/>
          <criterion comment="kernel-headers is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:93850"/>
          <criterion comment="python-perf is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:94230"/>
          <criterion comment="perf is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:94322"/>
          <criterion comment="kernel-kdump is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:94435"/>
          <criterion comment="kernel-firmware is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:94277"/>
          <criterion comment="kernel-debug-devel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:93841"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:94453"/>
          <criterion comment="kernel-debug is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:93851"/>
          <criterion comment="kernel-bootwrapper is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:94258"/>
          <criterion comment="kernel is earlier than 0:2.6.32-279.5.1.el6" test_ref="oval:org.mitre.oval:tst:94021"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20645" version="289" class="patch">
      <metadata>
        <title>RHSA-2012:1392: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1392-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1392.html"/>
        <reference source="CVE" ref_id="CVE-2012-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0547.html"/>
        <reference source="CVE" ref_id="CVE-2012-1531" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1531.html"/>
        <reference source="CVE" ref_id="CVE-2012-1532" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1532.html"/>
        <reference source="CVE" ref_id="CVE-2012-1533" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1533.html"/>
        <reference source="CVE" ref_id="CVE-2012-3143" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3143.html"/>
        <reference source="CVE" ref_id="CVE-2012-3159" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3159.html"/>
        <reference source="CVE" ref_id="CVE-2012-3216" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3216.html"/>
        <reference source="CVE" ref_id="CVE-2012-4416" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4416.html"/>
        <reference source="CVE" ref_id="CVE-2012-5068" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5068.html"/>
        <reference source="CVE" ref_id="CVE-2012-5069" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5069.html"/>
        <reference source="CVE" ref_id="CVE-2012-5071" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5071.html"/>
        <reference source="CVE" ref_id="CVE-2012-5072" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5072.html"/>
        <reference source="CVE" ref_id="CVE-2012-5073" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5073.html"/>
        <reference source="CVE" ref_id="CVE-2012-5075" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5075.html"/>
        <reference source="CVE" ref_id="CVE-2012-5077" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5077.html"/>
        <reference source="CVE" ref_id="CVE-2012-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5079.html"/>
        <reference source="CVE" ref_id="CVE-2012-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5081.html"/>
        <reference source="CVE" ref_id="CVE-2012-5083" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5083.html"/>
        <reference source="CVE" ref_id="CVE-2012-5084" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5084.html"/>
        <reference source="CVE" ref_id="CVE-2012-5085" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5085.html"/>
        <reference source="CVE" ref_id="CVE-2012-5086" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5086.html"/>
        <reference source="CVE" ref_id="CVE-2012-5089" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-5089.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JMX.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:42.902-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:15.728-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:29.499-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94692"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94835"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94693"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94440"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94766"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.37-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:94253"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20642" version="299" class="patch">
      <metadata>
        <title>RHSA-2013:1509: java-1.5.0-ibm security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.5.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1509-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1509.html"/>
        <reference source="CVE" ref_id="CVE-2013-5774" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5774.html"/>
        <reference source="CVE" ref_id="CVE-2013-5778" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5778.html"/>
        <reference source="CVE" ref_id="CVE-2013-5780" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5780.html"/>
        <reference source="CVE" ref_id="CVE-2013-5782" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5782.html"/>
        <reference source="CVE" ref_id="CVE-2013-5783" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5783.html"/>
        <reference source="CVE" ref_id="CVE-2013-5790" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5790.html"/>
        <reference source="CVE" ref_id="CVE-2013-5797" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5797.html"/>
        <reference source="CVE" ref_id="CVE-2013-5801" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5801.html"/>
        <reference source="CVE" ref_id="CVE-2013-5802" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5802.html"/>
        <reference source="CVE" ref_id="CVE-2013-5803" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5803.html"/>
        <reference source="CVE" ref_id="CVE-2013-5804" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5804.html"/>
        <reference source="CVE" ref_id="CVE-2013-5809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5809.html"/>
        <reference source="CVE" ref_id="CVE-2013-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5814.html"/>
        <reference source="CVE" ref_id="CVE-2013-5817" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5817.html"/>
        <reference source="CVE" ref_id="CVE-2013-5825" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5825.html"/>
        <reference source="CVE" ref_id="CVE-2013-5829" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5829.html"/>
        <reference source="CVE" ref_id="CVE-2013-5830" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5830.html"/>
        <reference source="CVE" ref_id="CVE-2013-5840" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5840.html"/>
        <reference source="CVE" ref_id="CVE-2013-5842" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5842.html"/>
        <reference source="CVE" ref_id="CVE-2013-5843" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5843.html"/>
        <reference source="CVE" ref_id="CVE-2013-5849" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5849.html"/>
        <description>Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality via vectors related to AWT.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:46.973-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:19.413-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:25.911-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20642 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:24.559-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:15.485-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137682"/>
            <criterion comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137753"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137820"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137845"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137839"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137173"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137784"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.4-1jpp.1.el5_10" test_ref="oval:org.mitre.oval:tst:137461"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91630"/>
            <criterion comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91332"/>
            <criterion comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91325"/>
            <criterion comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91727"/>
            <criterion comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91915"/>
            <criterion comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91799"/>
            <criterion comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.4-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91583"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20636" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0788: subscription-manager security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>subscription-manager</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0788-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0788.html"/>
        <reference source="CVE" ref_id="CVE-2012-6137" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-6137.html"/>
        <description>rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain sensitive information such as user credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:16.174-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:19.247-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:25.700-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="subscription-manager-firstboot is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:90947"/>
            <criterion comment="subscription-manager-gui is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:91230"/>
            <criterion comment="subscription-manager-migration is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:91218"/>
            <criterion comment="subscription-manager is earlier than 0:1.1.23.1-1.el6_4" test_ref="oval:org.mitre.oval:tst:91189"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="subscription-manager-firstboot is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:91246"/>
            <criterion comment="subscription-manager-gui is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:91199"/>
            <criterion comment="subscription-manager-migration is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:90783"/>
            <criterion comment="subscription-manager is earlier than 0:1.0.24.1-1.el5_9" test_ref="oval:org.mitre.oval:tst:90886"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20633" version="81" class="patch">
      <metadata>
        <title>RHSA-2012:0137: texlive security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>texlive</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0137-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0137.html"/>
        <reference source="CESA" ref_id="CESA-2012:0137"/>
        <reference source="CVE" ref_id="CVE-2010-2642" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-2642.html"/>
        <reference source="CVE" ref_id="CVE-2011-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0433.html"/>
        <reference source="CVE" ref_id="CVE-2011-0764" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-0764.html"/>
        <reference source="CVE" ref_id="CVE-2011-1552" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1552.html"/>
        <reference source="CVE" ref_id="CVE-2011-1553" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1553.html"/>
        <reference source="CVE" ref_id="CVE-2011-1554" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-1554.html"/>
        <description>Off-by-one error in t1lib 5.1.2 and earlier, as used in Xpdf before 3.02pl6, teTeX, and other products, allows remote attackers to cause a denial of service (application crash) via a PDF document containing a crafted Type 1 font that triggers an invalid memory read, integer overflow, and invalid pointer dereference, a different vulnerability than CVE-2011-0764.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:21:06.433-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:15.493-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:29.294-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="texlive-dvips is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:92793"/>
          <criterion comment="texlive-latex is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:92612"/>
          <criterion comment="kpathsea is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:93031"/>
          <criterion comment="texlive-context is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:92862"/>
          <criterion comment="texlive-afm is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:93021"/>
          <criterion comment="mendexk is earlier than 0:2.6e-57.el6_2" test_ref="oval:org.mitre.oval:tst:92193"/>
          <criterion comment="texlive-dviutils is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:92864"/>
          <criterion comment="texlive-east-asian is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:92928"/>
          <criterion comment="texlive-utils is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:92986"/>
          <criterion comment="texlive-xetex is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:93011"/>
          <criterion comment="kpathsea-devel is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:92877"/>
          <criterion comment="texlive is earlier than 0:2007-57.el6_2" test_ref="oval:org.mitre.oval:tst:92741"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20626" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1582: python security, bug fix, and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>python</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1582-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1582.html"/>
        <reference source="CESA" ref_id="CESA-2013:1582"/>
        <reference source="CVE" ref_id="CVE-2013-4238" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4238.html"/>
        <description>The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:01.937-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:19.084-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:25.505-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="tkinter is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:91567"/>
          <criterion comment="python-tools is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:91641"/>
          <criterion comment="python-test is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:91624"/>
          <criterion comment="python is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:91720"/>
          <criterion comment="python-libs is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:91853"/>
          <criterion comment="python-devel is earlier than 0:2.6.6-51.el6" test_ref="oval:org.mitre.oval:tst:91684"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20620" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0525: pcsc-lite security and bug fix update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>pcsc-lite</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0525-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0525.html"/>
        <reference source="CESA" ref_id="CESA-2013:0525"/>
        <reference source="CVE" ref_id="CVE-2010-4531" ref_url="https://www.redhat.com/security/data/cve/CVE-2010-4531.html"/>
        <description>Stack-based buffer overflow in the ATRDecodeAtr function in the Answer-to-Reset (ATR) Handler (atrhandler.c) for pcscd in PCSC-Lite 1.5.3, and possibly other 1.5.x and 1.6.x versions, allows physically proximate attackers to cause a denial of service (crash) and possibly execute arbitrary code via a smart card with an ATR message containing a long attribute value.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:46.384-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:18.966-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:25.355-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pcsc-lite-libs is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:90457"/>
          <criterion comment="pcsc-lite-devel is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:90350"/>
          <criterion comment="pcsc-lite is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:90701"/>
          <criterion comment="pcsc-lite-doc is earlier than 0:1.5.2-11.el6" test_ref="oval:org.mitre.oval:tst:90687"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20608" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:1141: dhcp security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>dhcp</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:1141-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-1141.html"/>
        <reference source="CESA" ref_id="CESA-2012:1141"/>
        <reference source="CVE" ref_id="CVE-2012-3571" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3571.html"/>
        <reference source="CVE" ref_id="CVE-2012-3954" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3954.html"/>
        <description>Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:58.860-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:15.381-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:29.138-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="dhclient is earlier than 12:4.1.1-31.P1.el6_3.1" test_ref="oval:org.mitre.oval:tst:93748"/>
          <criterion comment="dhcp-devel is earlier than 12:4.1.1-31.P1.el6_3.1" test_ref="oval:org.mitre.oval:tst:94448"/>
          <criterion comment="dhcp is earlier than 12:4.1.1-31.P1.el6_3.1" test_ref="oval:org.mitre.oval:tst:94338"/>
          <criterion comment="dhcp-common is earlier than 12:4.1.1-31.P1.el6_3.1" test_ref="oval:org.mitre.oval:tst:94091"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20606" version="75" class="patch">
      <metadata>
        <title>RHSA-2013:1829: nss, nspr, and nss-util security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>nspr</product>
          <product>nss</product>
          <product>nss-util</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1829-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1829.html"/>
        <reference source="CESA" ref_id="CESA-2013:1829"/>
        <reference source="CVE" ref_id="CVE-2013-1739" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1739.html"/>
        <reference source="CVE" ref_id="CVE-2013-1741" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1741.html"/>
        <reference source="CVE" ref_id="CVE-2013-5605" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5605.html"/>
        <reference source="CVE" ref_id="CVE-2013-5606" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5606.html"/>
        <reference source="CVE" ref_id="CVE-2013-5607" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-5607.html"/>
        <description>Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:31.595-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:18.144-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:25.055-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20606 - Products and Centos critera added" date="2014-06-13T17:47:00.365-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-06-13T17:50:38.725-04:00">INTERIM</status_change>
            <status_change date="2014-06-30T04:09:06.922-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="nspr is earlier than 0:4.10.2-1.el6_5" test_ref="oval:org.mitre.oval:tst:91933"/>
          <criterion comment="nspr-devel is earlier than 0:4.10.2-1.el6_5" test_ref="oval:org.mitre.oval:tst:91921"/>
          <criterion comment="nss-util-devel is earlier than 0:3.15.3-1.el6_5" test_ref="oval:org.mitre.oval:tst:91975"/>
          <criterion comment="nss-util is earlier than 0:3.15.3-1.el6_5" test_ref="oval:org.mitre.oval:tst:92004"/>
          <criterion comment="nss-tools is earlier than 0:3.15.3-2.el6_5" test_ref="oval:org.mitre.oval:tst:91991"/>
          <criterion comment="nss-devel is earlier than 0:3.15.3-2.el6_5" test_ref="oval:org.mitre.oval:tst:91654"/>
          <criterion comment="nss-sysinit is earlier than 0:3.15.3-2.el6_5" test_ref="oval:org.mitre.oval:tst:91912"/>
          <criterion comment="nss is earlier than 0:3.15.3-2.el6_5" test_ref="oval:org.mitre.oval:tst:91575"/>
          <criterion comment="nss-pkcs11-devel is earlier than 0:3.15.3-2.el6_5" test_ref="oval:org.mitre.oval:tst:91416"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20604" version="87" class="patch">
      <metadata>
        <title>RHSA-2013:1140: firefox security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>firefox</product>
          <product>xulrunner</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1140-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1140.html"/>
        <reference source="CESA" ref_id="CESA-2013:1140"/>
        <reference source="CVE" ref_id="CVE-2013-1701" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1701.html"/>
        <reference source="CVE" ref_id="CVE-2013-1709" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1709.html"/>
        <reference source="CVE" ref_id="CVE-2013-1710" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1710.html"/>
        <reference source="CVE" ref_id="CVE-2013-1713" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1713.html"/>
        <reference source="CVE" ref_id="CVE-2013-1714" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1714.html"/>
        <reference source="CVE" ref_id="CVE-2013-1717" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1717.html"/>
        <description>Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly restrict local-filesystem access by Java applets, which allows user-assisted remote attackers to read arbitrary files by leveraging a download to a fixed pathname or other predictable pathname.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:18.500-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:17.781-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:24.539-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:17.0.8-1.el6_4" test_ref="oval:org.mitre.oval:tst:91594"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.el6_4" test_ref="oval:org.mitre.oval:tst:90631"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.el6_4" test_ref="oval:org.mitre.oval:tst:91370"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="firefox is earlier than 0:17.0.8-1.el6.centos" test_ref="oval:org.mitre.oval:tst:92028"/>
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.el6.centos" test_ref="oval:org.mitre.oval:tst:92196"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.el6.centos" test_ref="oval:org.mitre.oval:tst:91976"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 and Centos 5 section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xulrunner is earlier than 0:17.0.8-3.el5_9" test_ref="oval:org.mitre.oval:tst:91285"/>
            <criterion comment="xulrunner-devel is earlier than 0:17.0.8-3.el5_9" test_ref="oval:org.mitre.oval:tst:91530"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="firefox is earlier than 0:17.0.8-1.el5.centos" test_ref="oval:org.mitre.oval:tst:92126"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="firefox is earlier than 0:17.0.8-1.el5_9" test_ref="oval:org.mitre.oval:tst:90982"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20602" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0748: libvirt security, bug fix, and enhancement update (Low)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0748-05" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0748.html"/>
        <reference source="CESA" ref_id="CESA-2012:0748"/>
        <reference source="CVE" ref_id="CVE-2012-2693" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-2693.html"/>
        <description>libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:08.780-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:15.292-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:29.028-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="libvirt-devel is earlier than 0:0.9.10-21.el6" test_ref="oval:org.mitre.oval:tst:93707"/>
          <criterion comment="libvirt-python is earlier than 0:0.9.10-21.el6" test_ref="oval:org.mitre.oval:tst:93629"/>
          <criterion comment="libvirt-client is earlier than 0:0.9.10-21.el6" test_ref="oval:org.mitre.oval:tst:93577"/>
          <criterion comment="libvirt-lock-sanlock is earlier than 0:0.9.10-21.el6" test_ref="oval:org.mitre.oval:tst:93860"/>
          <criterion comment="libvirt is earlier than 0:0.9.10-21.el6" test_ref="oval:org.mitre.oval:tst:93689"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20598" version="423" class="patch">
      <metadata>
        <title>RHSA-2013:0236: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0236-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0236.html"/>
        <reference source="CVE" ref_id="CVE-2012-1541" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1541.html"/>
        <reference source="CVE" ref_id="CVE-2012-3213" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3213.html"/>
        <reference source="CVE" ref_id="CVE-2012-3342" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3342.html"/>
        <reference source="CVE" ref_id="CVE-2013-0351" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0351.html"/>
        <reference source="CVE" ref_id="CVE-2013-0409" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0409.html"/>
        <reference source="CVE" ref_id="CVE-2013-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0419.html"/>
        <reference source="CVE" ref_id="CVE-2013-0423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0423.html"/>
        <reference source="CVE" ref_id="CVE-2013-0424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0424.html"/>
        <reference source="CVE" ref_id="CVE-2013-0425" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0425.html"/>
        <reference source="CVE" ref_id="CVE-2013-0426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0426.html"/>
        <reference source="CVE" ref_id="CVE-2013-0427" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0427.html"/>
        <reference source="CVE" ref_id="CVE-2013-0428" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0428.html"/>
        <reference source="CVE" ref_id="CVE-2013-0429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0429.html"/>
        <reference source="CVE" ref_id="CVE-2013-0430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0430.html"/>
        <reference source="CVE" ref_id="CVE-2013-0432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0432.html"/>
        <reference source="CVE" ref_id="CVE-2013-0433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0433.html"/>
        <reference source="CVE" ref_id="CVE-2013-0434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0434.html"/>
        <reference source="CVE" ref_id="CVE-2013-0435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0435.html"/>
        <reference source="CVE" ref_id="CVE-2013-0438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0438.html"/>
        <reference source="CVE" ref_id="CVE-2013-0440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0440.html"/>
        <reference source="CVE" ref_id="CVE-2013-0441" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0441.html"/>
        <reference source="CVE" ref_id="CVE-2013-0442" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0442.html"/>
        <reference source="CVE" ref_id="CVE-2013-0443" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0443.html"/>
        <reference source="CVE" ref_id="CVE-2013-0445" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0445.html"/>
        <reference source="CVE" ref_id="CVE-2013-0446" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0446.html"/>
        <reference source="CVE" ref_id="CVE-2013-0450" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0450.html"/>
        <reference source="CVE" ref_id="CVE-2013-1473" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1473.html"/>
        <reference source="CVE" ref_id="CVE-2013-1475" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1475.html"/>
        <reference source="CVE" ref_id="CVE-2013-1476" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1476.html"/>
        <reference source="CVE" ref_id="CVE-2013-1478" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1478.html"/>
        <reference source="CVE" ref_id="CVE-2013-1480" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1480.html"/>
        <reference source="CVE" ref_id="CVE-2013-1481" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1481.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Sound.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:43.740-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:16.565-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:22.479-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.39-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90476"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.39-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90320"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.39-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90144"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.39-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90306"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.39-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90388"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.39-1jpp.1.el6_3" test_ref="oval:org.mitre.oval:tst:90412"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20593" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0612: ruby security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>ruby</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0612-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0612.html"/>
        <reference source="CESA" ref_id="CESA-2013:0612"/>
        <reference source="CVE" ref_id="CVE-2012-4481" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4481.html"/>
        <reference source="CVE" ref_id="CVE-2013-1821" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1821.html"/>
        <description>lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:16.939-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:16.407-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:22.259-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="ruby is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:90650"/>
          <criterion comment="ruby-rdoc is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:90659"/>
          <criterion comment="ruby-devel is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:90719"/>
          <criterion comment="ruby-tcltk is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:90830"/>
          <criterion comment="ruby-docs is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:90769"/>
          <criterion comment="ruby-static is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:90914"/>
          <criterion comment="ruby-irb is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:90433"/>
          <criterion comment="ruby-libs is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:90859"/>
          <criterion comment="ruby-ri is earlier than 0:1.8.7.352-10.el6_4" test_ref="oval:org.mitre.oval:tst:90821"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20583" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0429: gnutls security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>gnutls</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0429-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0429.html"/>
        <reference source="CESA" ref_id="CESA-2012:0429"/>
        <reference source="CVE" ref_id="CVE-2011-4128" ref_url="https://www.redhat.com/security/data/cve/CVE-2011-4128.html"/>
        <reference source="CVE" ref_id="CVE-2012-1573" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1573.html"/>
        <description>gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) via a crafted record, as demonstrated by a crafted GenericBlockCipher structure.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:39.773-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:15.045-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:28.668-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="gnutls is earlier than 0:2.8.5-4.el6_2.2" test_ref="oval:org.mitre.oval:tst:93135"/>
          <criterion comment="gnutls-devel is earlier than 0:2.8.5-4.el6_2.2" test_ref="oval:org.mitre.oval:tst:92970"/>
          <criterion comment="gnutls-utils is earlier than 0:2.8.5-4.el6_2.2" test_ref="oval:org.mitre.oval:tst:93241"/>
          <criterion comment="gnutls-guile is earlier than 0:2.8.5-4.el6_2.2" test_ref="oval:org.mitre.oval:tst:93261"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20562" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0156: java-1.7.0-oracle security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.7.0-oracle</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0156-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0156.html"/>
        <reference source="CVE" ref_id="CVE-2012-3174" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-3174.html"/>
        <reference source="CVE" ref_id="CVE-2013-0422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0422.html"/>
        <description>Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114.  CVE-2013-0422 covers both the JMX/MBean and Reflection API issues.  NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks.  NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11.  If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:17.137-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:15.912-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:21.338-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.7.0-oracle is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90347"/>
          <criterion comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90090"/>
          <criterion comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90220"/>
          <criterion comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90327"/>
          <criterion comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90177"/>
          <criterion comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.11-1jpp.3.el6_3" test_ref="oval:org.mitre.oval:tst:90373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20541" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0731: expat security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>expat</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0731-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0731.html"/>
        <reference source="CESA" ref_id="CESA-2012:0731"/>
        <reference source="CVE" ref_id="CVE-2012-0876" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0876.html"/>
        <reference source="CVE" ref_id="CVE-2012-1148" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1148.html"/>
        <description>Memory leak in the poolGrow function in expat/lib/xmlparse.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (memory consumption) via a large number of crafted XML files that cause improperly-handled reallocation failures when expanding entities.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:18:45.074-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:14.663-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:28.232-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="expat-devel is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:93627"/>
            <criterion comment="expat is earlier than 0:1.95.8-11.el5_8" test_ref="oval:org.mitre.oval:tst:93421"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="expat-devel is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:93827"/>
            <criterion comment="expat is earlier than 0:2.0.1-11.el6_2" test_ref="oval:org.mitre.oval:tst:93425"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20538" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0511: pki-core security, bug fix and enhancement update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>pki-core</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0511-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0511.html"/>
        <reference source="CESA" ref_id="CESA-2013:0511"/>
        <reference source="CVE" ref_id="CVE-2012-4543" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-4543.html"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Certificate System (RHCS) before 8.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) pageStart or (2) pageSize to the displayCRL script, or (3) nonce variable to the profileProcess script.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:10.596-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:15.618-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:20.907-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="pki-ca is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90401"/>
          <criterion comment="pki-selinux is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90512"/>
          <criterion comment="pki-common is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90657"/>
          <criterion comment="pki-java-tools-javadoc is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90680"/>
          <criterion comment="pki-util is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90635"/>
          <criterion comment="pki-setup is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90522"/>
          <criterion comment="pki-core is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90662"/>
          <criterion comment="pki-util-javadoc is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90562"/>
          <criterion comment="pki-silent is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90061"/>
          <criterion comment="pki-native-tools is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90549"/>
          <criterion comment="pki-java-tools is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90690"/>
          <criterion comment="pki-common-javadoc is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90592"/>
          <criterion comment="pki-symkey is earlier than 0:9.0.3-30.el6" test_ref="oval:org.mitre.oval:tst:90686"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20474" version="4" class="patch">
      <metadata>
        <title>RHSA-2012:0369: python-sqlalchemy security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>python-sqlalchemy</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0369-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0369.html"/>
        <reference source="CESA" ref_id="CESA-2012:0369"/>
        <reference source="CVE" ref_id="CVE-2012-0805" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0805.html"/>
        <description>Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset keyword to the select function, or unspecified vectors to the (3) select.limit or (4) select.offset function.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:05.352-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:14.482-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:28.026-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="python-sqlalchemy is earlier than 0:0.5.5-3.el6_2" test_ref="oval:org.mitre.oval:tst:92426"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="The operating system installed on the system is CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20471" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0868: haproxy security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>haproxy</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0868-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0868.html"/>
        <reference source="CESA" ref_id="CESA-2013:0868"/>
        <reference source="CVE" ref_id="CVE-2013-1912" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1912.html"/>
        <description>Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends to requests, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted pipelined HTTP requests that prevent request realignment from occurring.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:47.113-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:15.241-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:20.446-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="haproxy is earlier than 0:1.4.22-4.el6_4" test_ref="oval:org.mitre.oval:tst:91245"/>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20467" version="283" class="patch">
      <metadata>
        <title>RHSA-2013:0770: java-1.6.0-openjdk security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0770-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0770.html"/>
        <reference source="CESA" ref_id="CESA-2013:0770"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1488" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1488.html"/>
        <reference source="CVE" ref_id="CVE-2013-1518" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1518.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1558.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2415.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2421" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2421.html"/>
        <reference source="CVE" ref_id="CVE-2013-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2422.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2426.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2431" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2431.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to HotSpot.  NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to bypassing the Java sandbox using "method handle intrinsic frames."</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:11.639-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:14.288-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:19.937-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:91183"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:91018"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:91229"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:91269"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.61.1.11.11.el6_4" test_ref="oval:org.mitre.oval:tst:91263"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:91271"/>
            <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:91258"/>
            <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:91198"/>
            <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:91207"/>
            <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.11.11.el5_9" test_ref="oval:org.mitre.oval:tst:91091"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20445" version="29" class="patch">
      <metadata>
        <title>RHSA-2012:0359: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0359-01" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0359.html"/>
        <reference source="CVE" ref_id="CVE-2012-0768" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0768.html"/>
        <reference source="CVE" ref_id="CVE-2012-0769" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0769.html"/>
        <description>Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x; and before 11.1.115.7 on Android 4.x does not properly handle integers, which allows attackers to obtain sensitive information via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:19:55.929-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:14.355-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:27.787-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.16-1.el5" test_ref="oval:org.mitre.oval:tst:92839"/>
        </criteria>
        <criteria comment="Operation system section">
          <criterion comment="flash-plugin is earlier than 0:10.3.183.16-1.el6" test_ref="oval:org.mitre.oval:tst:92837"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20442" version="355" class="patch">
      <metadata>
        <title>RHSA-2013:0150: acroread security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>acroread</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0150-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0150.html"/>
        <reference source="CVE" ref_id="CVE-2012-1530" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-1530.html"/>
        <reference source="CVE" ref_id="CVE-2013-0601" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0601.html"/>
        <reference source="CVE" ref_id="CVE-2013-0602" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0602.html"/>
        <reference source="CVE" ref_id="CVE-2013-0603" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0603.html"/>
        <reference source="CVE" ref_id="CVE-2013-0604" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0604.html"/>
        <reference source="CVE" ref_id="CVE-2013-0605" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0605.html"/>
        <reference source="CVE" ref_id="CVE-2013-0606" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0606.html"/>
        <reference source="CVE" ref_id="CVE-2013-0607" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0607.html"/>
        <reference source="CVE" ref_id="CVE-2013-0608" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0608.html"/>
        <reference source="CVE" ref_id="CVE-2013-0609" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0609.html"/>
        <reference source="CVE" ref_id="CVE-2013-0610" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0610.html"/>
        <reference source="CVE" ref_id="CVE-2013-0611" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0611.html"/>
        <reference source="CVE" ref_id="CVE-2013-0612" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0612.html"/>
        <reference source="CVE" ref_id="CVE-2013-0613" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0613.html"/>
        <reference source="CVE" ref_id="CVE-2013-0614" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0614.html"/>
        <reference source="CVE" ref_id="CVE-2013-0615" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0615.html"/>
        <reference source="CVE" ref_id="CVE-2013-0616" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0616.html"/>
        <reference source="CVE" ref_id="CVE-2013-0617" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0617.html"/>
        <reference source="CVE" ref_id="CVE-2013-0618" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0618.html"/>
        <reference source="CVE" ref_id="CVE-2013-0619" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0619.html"/>
        <reference source="CVE" ref_id="CVE-2013-0620" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0620.html"/>
        <reference source="CVE" ref_id="CVE-2013-0621" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0621.html"/>
        <reference source="CVE" ref_id="CVE-2013-0623" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0623.html"/>
        <reference source="CVE" ref_id="CVE-2013-0626" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0626.html"/>
        <reference source="CVE" ref_id="CVE-2013-1376" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1376.html"/>
        <description>Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0606, CVE-2013-0612, CVE-2013-0615, CVE-2013-0617, and CVE-2013-0621.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:48.385-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:13.559-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:18.855-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20442 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:28.481-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:13.455-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:137718"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.3-1.el5_9" test_ref="oval:org.mitre.oval:tst:137517"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="acroread is earlier than 0:9.5.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:90378"/>
            <criterion comment="acroread-plugin is earlier than 0:9.5.3-1.el6_3" test_ref="oval:org.mitre.oval:tst:90196"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20438" version="47" class="patch">
      <metadata>
        <title>RHSA-2013:0574: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0574-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0574.html"/>
        <reference source="CVE" ref_id="CVE-2013-0504" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0504.html"/>
        <reference source="CVE" ref_id="CVE-2013-0643" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0643.html"/>
        <reference source="CVE" ref_id="CVE-2013-0648" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0648.html"/>
        <description>Unspecified vulnerability in the ExternalInterface ActionScript functionality in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:21.134-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:13.313-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:18.571-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20438 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:21.780-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:12.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.273-1.el5" test_ref="oval:org.mitre.oval:tst:137667"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:11.2.202.273-1.el6" test_ref="oval:org.mitre.oval:tst:90634"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20435" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0689: bind security and bug fix update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>bind</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0689-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0689.html"/>
        <reference source="CESA" ref_id="CESA-2013:0689"/>
        <reference source="CVE" ref_id="CVE-2013-2266" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2266.html"/>
        <description>libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as demonstrated by a memory-exhaustion attack against a machine running a named process.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:40.666-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:13.187-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:18.430-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="bind is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:90997"/>
          <criterion comment="bind-chroot is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:90185"/>
          <criterion comment="bind-sdb is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:90998"/>
          <criterion comment="bind-libs is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:90852"/>
          <criterion comment="bind-utils is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:90405"/>
          <criterion comment="bind-devel is earlier than 32:9.8.2-0.17.rc1.el6_4.4" test_ref="oval:org.mitre.oval:tst:90596"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20413" version="83" class="patch">
      <metadata>
        <title>RHSA-2012:0144: flash-plugin security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>flash-plugin</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2012:0144-02" ref_url="https://rhn.redhat.com/errata/RHSA-2012-0144.html"/>
        <reference source="CVE" ref_id="CVE-2012-0752" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0752.html"/>
        <reference source="CVE" ref_id="CVE-2012-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0753.html"/>
        <reference source="CVE" ref_id="CVE-2012-0754" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0754.html"/>
        <reference source="CVE" ref_id="CVE-2012-0755" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0755.html"/>
        <reference source="CVE" ref_id="CVE-2012-0756" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0756.html"/>
        <reference source="CVE" ref_id="CVE-2012-0767" ref_url="https://www.redhat.com/security/data/cve/CVE-2012-0767.html"/>
        <description>Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-14T18:40:22">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-15T12:20:42.624-05:00">DRAFT</status_change>
            <status_change date="2014-02-03T04:01:14.143-05:00">INTERIM</status_change>
            <status_change date="2014-02-24T04:00:27.412-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20413 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:27.370-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:12.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.15-1.el5" test_ref="oval:org.mitre.oval:tst:137012"/>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criterion comment="flash-plugin is earlier than 0:10.3.183.15-1.el6" test_ref="oval:org.mitre.oval:tst:92921"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20333" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0605: java-1.6.0-openjdk security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>java-1.6.0-openjdk</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0605-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0605.html"/>
        <reference source="CESA" ref_id="CESA-2013:0605"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:50.339-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:12.403-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:17.631-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:90764"/>
          <criterion comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:90870"/>
          <criterion comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:90050"/>
          <criterion comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:90876"/>
          <criterion comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.57.1.11.9.el6_4" test_ref="oval:org.mitre.oval:tst:90247"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20286" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:1182: 389-ds-base security update (Important)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 6</platform>
          <product>389-ds-base</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:1182-00" ref_url="https://rhn.redhat.com/errata/RHSA-2013-1182.html"/>
        <reference source="CESA" ref_id="CESA-2013:1182"/>
        <reference source="CVE" ref_id="CVE-2013-4283" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-4283.html"/>
        <description>ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:57:28.148-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:11.948-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:17.172-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="389-ds-base-libs is earlier than 0:1.2.11.15-22.el6_4" test_ref="oval:org.mitre.oval:tst:91597"/>
          <criterion comment="389-ds-base is earlier than 0:1.2.11.15-22.el6_4" test_ref="oval:org.mitre.oval:tst:91356"/>
          <criterion comment="389-ds-base-devel is earlier than 0:1.2.11.15-22.el6_4" test_ref="oval:org.mitre.oval:tst:91678"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20280" version="4" class="patch">
      <metadata>
        <title>RHSA-2013:0771: curl security update (Moderate)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0771-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0771.html"/>
        <reference source="CESA" ref_id="CESA-2013:0771"/>
        <reference source="CVE" ref_id="CVE-2013-1944" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1944.html"/>
        <description>The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:11.143-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:11.783-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:17.006-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 6 or Centos 6 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
            <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="curl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:91134"/>
            <criterion comment="libcurl-devel is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:91228"/>
            <criterion comment="libcurl is earlier than 0:7.19.7-36.el6_4" test_ref="oval:org.mitre.oval:tst:90748"/>
          </criteria>
        </criteria>
        <criteria comment="Operation system section">
          <criteria operator="OR" comment="Redhat 5 or Centos 5 release">
            <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
            <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="curl is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:91106"/>
            <criterion comment="curl-devel is earlier than 0:7.15.5-16.el5_9" test_ref="oval:org.mitre.oval:tst:90771"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20254" version="453" class="patch">
      <metadata>
        <title>RHSA-2013:0822: java-1.7.0-ibm security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
          <product>java-1.7.0-ibm</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0822-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0822.html"/>
        <reference source="CVE" ref_id="CVE-2013-0169" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0169.html"/>
        <reference source="CVE" ref_id="CVE-2013-0401" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0401.html"/>
        <reference source="CVE" ref_id="CVE-2013-1488" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1488.html"/>
        <reference source="CVE" ref_id="CVE-2013-1491" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1491.html"/>
        <reference source="CVE" ref_id="CVE-2013-1537" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1537.html"/>
        <reference source="CVE" ref_id="CVE-2013-1540" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1540.html"/>
        <reference source="CVE" ref_id="CVE-2013-1557" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1557.html"/>
        <reference source="CVE" ref_id="CVE-2013-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1558.html"/>
        <reference source="CVE" ref_id="CVE-2013-1563" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1563.html"/>
        <reference source="CVE" ref_id="CVE-2013-1569" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1569.html"/>
        <reference source="CVE" ref_id="CVE-2013-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2383.html"/>
        <reference source="CVE" ref_id="CVE-2013-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2384.html"/>
        <reference source="CVE" ref_id="CVE-2013-2394" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2394.html"/>
        <reference source="CVE" ref_id="CVE-2013-2415" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2415.html"/>
        <reference source="CVE" ref_id="CVE-2013-2416" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2416.html"/>
        <reference source="CVE" ref_id="CVE-2013-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2417.html"/>
        <reference source="CVE" ref_id="CVE-2013-2418" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2418.html"/>
        <reference source="CVE" ref_id="CVE-2013-2419" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2419.html"/>
        <reference source="CVE" ref_id="CVE-2013-2420" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2420.html"/>
        <reference source="CVE" ref_id="CVE-2013-2422" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2422.html"/>
        <reference source="CVE" ref_id="CVE-2013-2423" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2423.html"/>
        <reference source="CVE" ref_id="CVE-2013-2424" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2424.html"/>
        <reference source="CVE" ref_id="CVE-2013-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2426.html"/>
        <reference source="CVE" ref_id="CVE-2013-2429" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2429.html"/>
        <reference source="CVE" ref_id="CVE-2013-2430" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2430.html"/>
        <reference source="CVE" ref_id="CVE-2013-2432" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2432.html"/>
        <reference source="CVE" ref_id="CVE-2013-2433" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2433.html"/>
        <reference source="CVE" ref_id="CVE-2013-2434" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2434.html"/>
        <reference source="CVE" ref_id="CVE-2013-2435" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2435.html"/>
        <reference source="CVE" ref_id="CVE-2013-2436" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2436.html"/>
        <reference source="CVE" ref_id="CVE-2013-2438" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2438.html"/>
        <reference source="CVE" ref_id="CVE-2013-2440" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-2440.html"/>
        <description>Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2013-2435.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:33.801-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:10.596-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:15.663-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20254 - RHEL and Centos checks were added where necessary" date="2015-02-16T13:05:00.404-05:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2015-02-16T13:08:21.503-05:00">INTERIM</status_change>
            <status_change date="2015-03-09T04:00:08.547-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Red Hat Enterprise Linux 5 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137658"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137598"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:136863"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137553"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137834"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.4.2-1jpp.1.el5_9" test_ref="oval:org.mitre.oval:tst:137326"/>
          </criteria>
        </criteria>
        <criteria comment="Red Hat Enterprise Linux 6 release section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
          <criteria operator="OR" comment="Packages match section">
            <criterion comment="java-1.7.0-ibm is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91005"/>
            <criterion comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91076"/>
            <criterion comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91184"/>
            <criterion comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91162"/>
            <criterion comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91211"/>
            <criterion comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.4.2-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:91236"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20230" version="171" class="patch">
      <metadata>
        <title>RHSA-2013:0145: thunderbird security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
          <platform>Red Hat Enterprise Linux 6</platform>
          <platform>CentOS Linux 5</platform>
          <platform>CentOS Linux 6</platform>
          <product>thunderbird</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0145-01" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0145.html"/>
        <reference source="CESA" ref_id="CESA-2013:0145"/>
        <reference source="CVE" ref_id="CVE-2013-0744" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0744.html"/>
        <reference source="CVE" ref_id="CVE-2013-0746" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0746.html"/>
        <reference source="CVE" ref_id="CVE-2013-0748" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0748.html"/>
        <reference source="CVE" ref_id="CVE-2013-0750" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0750.html"/>
        <reference source="CVE" ref_id="CVE-2013-0753" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0753.html"/>
        <reference source="CVE" ref_id="CVE-2013-0754" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0754.html"/>
        <reference source="CVE" ref_id="CVE-2013-0758" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0758.html"/>
        <reference source="CVE" ref_id="CVE-2013-0759" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0759.html"/>
        <reference source="CVE" ref_id="CVE-2013-0762" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0762.html"/>
        <reference source="CVE" ref_id="CVE-2013-0766" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0766.html"/>
        <reference source="CVE" ref_id="CVE-2013-0767" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0767.html"/>
        <reference source="CVE" ref_id="CVE-2013-0769" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0769.html"/>
        <description>Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:56:10.494-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:09.756-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:14.390-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Redhat 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el6_3" test_ref="oval:org.mitre.oval:tst:90121"/>
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        </criteria>
        <criteria operator="AND" comment="Centos 6 section">
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el6.centos" test_ref="oval:org.mitre.oval:tst:91450"/>
          <extend_definition comment="CentOS Linux 6.x" definition_ref="oval:org.mitre.oval:def:16337"/>
        </criteria>
        <criteria operator="AND" comment="Redhat 5 section">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el5_9" test_ref="oval:org.mitre.oval:tst:90328"/>
        </criteria>
        <criteria operator="AND" comment="Centos 5 section">
          <extend_definition comment="CentOS Linux 5.x" definition_ref="oval:org.mitre.oval:def:15802"/>
          <criterion comment="thunderbird is earlier than 0:10.0.12-3.el5.centos" test_ref="oval:org.mitre.oval:tst:91722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16337" version="5" class="inventory">
      <metadata>
        <title>The operating system installed on the system is CentOS Linux 6.x</title>
        <affected family="unix">
          <platform>CentOS Linux 6</platform>
        </affected>
        <reference ref_id="cpe:/o:centos:centos:6" source="CPE"/>
        <description>The operating system installed on the system is CentOS Linux 6.x</description>
        <oval_repository>
          <dates>
            <submitted date="2013-03-05T10:00:00.000-00:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2013-03-06T10:17:12.235-05:00">DRAFT</status_change>
            <status_change date="2013-03-25T04:00:27.566-04:00">INTERIM</status_change>
            <status_change date="2013-04-15T04:00:16.187-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:16337 - new definitions (patch) for the CentOS &amp; RedHat 2012." date="2014-01-15T12:02:00.592-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2014-01-15T12:21:47.462-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:00:42.138-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Unix family" test_ref="oval:org.mitre.oval:tst:4424"/>
        <criterion comment="CentOS Linux 6.x is installed" test_ref="oval:org.mitre.oval:tst:80900"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15802" version="7" class="inventory">
      <metadata>
        <title>The operating system installed on the system is CentOS Linux 5.x</title>
        <affected family="unix">
          <platform>CentOS Linux 5</platform>
        </affected>
        <reference ref_id="cpe:/o:centos:centos:5" source="CPE"/>
        <description>The operating system installed on the system is CentOS Linux 5.x</description>
        <oval_repository>
          <dates>
            <submitted date="2012-12-11T10:36:00.000-05:00">
              <contributor organization="MITRE">Danny Haynes</contributor>
            </submitted>
            <status_change date="2012-12-12T17:30:41.244-05:00">DRAFT</status_change>
            <status_change date="2012-12-31T04:01:31.486-05:00">INTERIM</status_change>
            <status_change date="2013-01-21T04:00:13.958-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:20137 - Expanded the vulnerability checks for RHEL 3, 4, and 5 to cover  CentOS 3, 4, 5 and Oracle Linux 4 and 5" date="2013-04-10T14:46:00.236-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-04-10T15:20:38.109-04:00">INTERIM</status_change>
            <status_change date="2013-04-29T04:16:16.163-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:15802 - new definitions (patch) for the CentOS &amp; RedHat 2012." date="2014-01-15T12:02:00.592-05:00">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </modified>
            <status_change date="2014-01-15T12:21:47.538-05:00">INTERIM</status_change>
            <status_change date="2014-02-03T04:00:37.998-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="the installed operating system is part of the Unix family" test_ref="oval:org.mitre.oval:tst:4424"/>
        <criterion comment="CentOS Linux 5.x is installed" test_ref="oval:org.mitre.oval:tst:80416"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11414" version="7" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 5</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:5"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 5.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-06T12:00:00.000-06:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:09:29.872-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:09:16.744-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:10:00.824-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:11414 - Updated CPE reference, updated regular expression" date="2011-02-17T13:31:00.837-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-02-17T13:32:08.284-05:00">INTERIM</status_change>
            <status_change date="2011-03-07T04:00:03.934-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:11314 - Corrected - right version for brlapi and brlapi-devel as specified by RHSA-2010:0181-5" date="2013-03-18T12:26:00.995-04:00">
              <contributor organization="G2, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2013-03-18T12:31:15.870-04:00">INTERIM</status_change>
            <status_change date="2013-04-08T04:00:06.890-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 5 is installed" test_ref="oval:org.mitre.oval:tst:3846"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20185" version="31" class="patch">
      <metadata>
        <title>RHSA-2013:0601: java-1.6.0-sun security update (Critical)</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
          <product>java-1.6.0-sun</product>
        </affected>
        <reference source="VENDOR" ref_id="RHSA-2013:0601-02" ref_url="https://rhn.redhat.com/errata/RHSA-2013-0601.html"/>
        <reference source="CVE" ref_id="CVE-2013-0809" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-0809.html"/>
        <reference source="CVE" ref_id="CVE-2013-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2013-1493.html"/>
        <description>The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.</description>
        <oval_repository>
          <dates>
            <submitted date="2014-01-09T13:03:25">
              <contributor organization="ALTX-SOFT">Sergey Artykhov</contributor>
            </submitted>
            <status_change date="2014-01-10T12:58:00.361-05:00">DRAFT</status_change>
            <status_change date="2014-01-27T04:00:08.884-05:00">INTERIM</status_change>
            <status_change date="2014-02-17T04:00:13.804-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 6" definition_ref="oval:org.mitre.oval:def:20273"/>
        <criteria operator="OR" comment="Packages section">
          <criterion comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90773"/>
          <criterion comment="java-1.6.0-sun is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90726"/>
          <criterion comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90735"/>
          <criterion comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90857"/>
          <criterion comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90842"/>
          <criterion comment="java-1.6.0-sun-src is earlier than 1:1.6.0.43-1jpp.1.el6_4" test_ref="oval:org.mitre.oval:tst:90898"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20273" version="6" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 6</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 6</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:6"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 6.</description>
        <oval_repository>
          <dates>
            <submitted date="2013-12-09T13:03:37">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </submitted>
            <status_change date="2013-12-10T12:34:55.121-05:00">DRAFT</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:28686 - modified object oval:org.mitre.oval:obj:28686. regex was added to make the inventory more general." date="2013-12-13T11:11:00.085-05:00">
              <contributor organization="ALTX-SOFT">Maria Kedovskaya</contributor>
            </modified>
            <status_change date="2013-12-30T04:00:35.434-05:00">INTERIM</status_change>
            <status_change date="2014-01-20T04:00:35.410-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:20273 - new criterion was added to avoid operation in Oracle Linux system" date="2014-05-08T11:04:00.653-04:00">
              <contributor organization="ALTX-SOFT">Maria Mikhno</contributor>
            </modified>
            <status_change date="2014-05-08T11:06:06.167-04:00">INTERIM</status_change>
            <status_change date="2014-05-26T04:00:11.457-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 6 is installed" test_ref="oval:org.mitre.oval:tst:88889"/>
        <criterion negate="true" comment="Oracle Linux 6.x is installed" test_ref="oval:org.mitre.oval:tst:80772"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <rpminfo_test id="oval:org.mitre.oval:tst:140038" version="1" comment="perf-debuginfo is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42724"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139855" version="1" comment="kernel-firmware is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139845" version="1" comment="perf is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139839" version="1" comment="kernel-doc is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139820" version="1" comment="python-perf-debuginfo is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43043"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139816" version="1" comment="kernel-debuginfo is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42117"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139814" version="1" comment="kernel is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139760" version="1" comment="kernel-headers is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139745" version="1" comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42704"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139594" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139592" version="1" comment="kernel-debug-debuginfo is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42590"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139497" version="1" comment="python-perf is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139355" version="1" comment="kernel-devel is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139245" version="1" comment="kernel-debug is earlier than 0:2.6.32-358.59.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:38868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140224" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140221" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140204" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140190" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140123" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140122" version="1" comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42919"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140101" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140057" version="1" comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42919"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140018" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139981" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139980" version="1" comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42919"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139857" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139711" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:38315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139697" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:38912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139601" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139599" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139581" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139368" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.35-1.13.7.1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:39197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140028" version="1" comment="java-1.8.0-openjdk-debuginfo is earlier than 1:1.8.0.45-28.b13.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43900"/>
      <state state_ref="oval:org.mitre.oval:ste:39135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140012" version="1" comment="java-1.8.0-openjdk-demo is earlier than 1:1.8.0.45-30.b13.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42346"/>
      <state state_ref="oval:org.mitre.oval:ste:38262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139991" version="1" comment="java-1.8.0-openjdk-src is earlier than 1:1.8.0.45-30.b13.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42385"/>
      <state state_ref="oval:org.mitre.oval:ste:38262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139971" version="1" comment="java-1.8.0-openjdk-javadoc is earlier than 1:1.8.0.45-28.b13.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42445"/>
      <state state_ref="oval:org.mitre.oval:ste:39135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139969" version="1" comment="java-1.8.0-openjdk-debuginfo is earlier than 1:1.8.0.45-30.b13.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43900"/>
      <state state_ref="oval:org.mitre.oval:ste:38262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139924" version="1" comment="java-1.8.0-openjdk-accessibility is earlier than 1:1.8.0.45-30.b13.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44123"/>
      <state state_ref="oval:org.mitre.oval:ste:38262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139892" version="1" comment="java-1.8.0-openjdk-devel is earlier than 1:1.8.0.45-30.b13.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42172"/>
      <state state_ref="oval:org.mitre.oval:ste:38262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139811" version="1" comment="java-1.8.0-openjdk is earlier than 1:1.8.0.45-30.b13.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41937"/>
      <state state_ref="oval:org.mitre.oval:ste:38262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139729" version="1" comment="java-1.8.0-openjdk-src is earlier than 1:1.8.0.45-28.b13.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42385"/>
      <state state_ref="oval:org.mitre.oval:ste:39135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139726" version="1" comment="java-1.8.0-openjdk-headless is earlier than 1:1.8.0.45-30.b13.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42427"/>
      <state state_ref="oval:org.mitre.oval:ste:38262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139717" version="1" comment="java-1.8.0-openjdk-javadoc is earlier than 1:1.8.0.45-30.b13.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42445"/>
      <state state_ref="oval:org.mitre.oval:ste:38262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139713" version="1" comment="java-1.8.0-openjdk-demo is earlier than 1:1.8.0.45-28.b13.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42346"/>
      <state state_ref="oval:org.mitre.oval:ste:39135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139360" version="1" comment="java-1.8.0-openjdk is earlier than 1:1.8.0.45-28.b13.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41937"/>
      <state state_ref="oval:org.mitre.oval:ste:39135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139277" version="1" comment="java-1.8.0-openjdk-headless is earlier than 1:1.8.0.45-28.b13.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42427"/>
      <state state_ref="oval:org.mitre.oval:ste:39135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139222" version="1" comment="java-1.8.0-openjdk-devel is earlier than 1:1.8.0.45-28.b13.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42172"/>
      <state state_ref="oval:org.mitre.oval:ste:39135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138926" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.448.el6_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37216"/>
      <state state_ref="oval:org.mitre.oval:ste:38768"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138836" version="1" comment="qemu-kvm-debuginfo is earlier than 2:0.12.1.2-2.448.el6_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42615"/>
      <state state_ref="oval:org.mitre.oval:ste:38768"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138677" version="1" comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.448.el6_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28988"/>
      <state state_ref="oval:org.mitre.oval:ste:38768"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138661" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.448.el6_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37253"/>
      <state state_ref="oval:org.mitre.oval:ste:38768"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137248" version="1" comment="rpm-devel is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29870"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137235" version="1" comment="rpm-python is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30203"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137213" version="1" comment="rpm-python is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30203"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137203" version="1" comment="rpm-debuginfo is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43266"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137172" version="1" comment="rpm-debuginfo is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43266"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137165" version="1" comment="rpm is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29900"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137066" version="1" comment="rpm-build is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30336"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137062" version="1" comment="rpm-devel is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29870"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137047" version="1" comment="rpm-cron is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29996"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137024" version="1" comment="rpm is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29900"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136922" version="1" comment="rpm-apidocs is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30029"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136878" version="1" comment="rpm-libs is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30299"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136811" version="1" comment="rpm-apidocs is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30029"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136793" version="1" comment="popt is earlier than 0:1.10.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29846"/>
      <state state_ref="oval:org.mitre.oval:ste:37311"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136765" version="1" comment="rpm-libs is earlier than 0:4.8.0-38.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30299"/>
      <state state_ref="oval:org.mitre.oval:ste:37720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136747" version="1" comment="rpm-build is earlier than 0:4.4.2.3-36.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30336"/>
      <state state_ref="oval:org.mitre.oval:ste:37167"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137394" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.15.0-25.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:37896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137387" version="1" comment="xorg-x11-server-common is earlier than 0:1.15.0-25.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28695"/>
      <state state_ref="oval:org.mitre.oval:ste:37896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137386" version="1" comment="xorg-x11-server-common is earlier than 0:1.15.0-7.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28695"/>
      <state state_ref="oval:org.mitre.oval:ste:38062"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137363" version="1" comment="xorg-x11-server-common is earlier than 0:1.15.0-25.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28695"/>
      <state state_ref="oval:org.mitre.oval:ste:38095"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137358" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.15.0-25.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:38095"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137352" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.15.0-25.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:37896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137307" version="1" comment="xorg-x11-server-debuginfo is earlier than 0:1.15.0-7.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42697"/>
      <state state_ref="oval:org.mitre.oval:ste:38062"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137300" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.15.0-7.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:38062"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137292" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.15.0-25.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:38095"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137275" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.15.0-25.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:37896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137254" version="1" comment="xorg-x11-server-devel is earlier than 0:1.15.0-25.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28915"/>
      <state state_ref="oval:org.mitre.oval:ste:37896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137234" version="1" comment="xorg-x11-server-source is earlier than 0:1.15.0-25.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28734"/>
      <state state_ref="oval:org.mitre.oval:ste:37896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137208" version="1" comment="xorg-x11-server-devel is earlier than 0:1.15.0-7.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28915"/>
      <state state_ref="oval:org.mitre.oval:ste:38062"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137191" version="1" comment="xorg-x11-server-source is earlier than 0:1.15.0-7.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28734"/>
      <state state_ref="oval:org.mitre.oval:ste:38062"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137157" version="1" comment="xorg-x11-server-debuginfo is earlier than 0:1.15.0-25.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42697"/>
      <state state_ref="oval:org.mitre.oval:ste:37896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137155" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.15.0-7.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:38062"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137148" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.15.0-7.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:38062"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137108" version="1" comment="xorg-x11-server-devel is earlier than 0:1.15.0-25.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28915"/>
      <state state_ref="oval:org.mitre.oval:ste:38095"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137065" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.15.0-25.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:38095"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137019" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.15.0-25.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:37896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136868" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.15.0-7.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:38062"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136768" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.15.0-25.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:38095"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136669" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.15.0-25.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:37896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136605" version="1" comment="xorg-x11-server-source is earlier than 0:1.15.0-25.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28734"/>
      <state state_ref="oval:org.mitre.oval:ste:38095"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136582" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.15.0-7.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:38062"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136401" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.15.0-25.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:38095"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140010" version="1" comment="java-1.7.0-openjdk-accessibility is earlier than 1:1.7.0.79-2.5.5.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39184"/>
      <state state_ref="oval:org.mitre.oval:ste:39208"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139983" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.79-2.5.5.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:39208"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139915" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.79-2.5.5.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:38295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139901" version="1" comment="java-1.7.0-openjdk-headless is earlier than 1:1.7.0.79-2.5.5.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38823"/>
      <state state_ref="oval:org.mitre.oval:ste:39208"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139893" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.79-2.5.5.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:38295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139872" version="1" comment="java-1.7.0-openjdk-debuginfo is earlier than 1:1.7.0.79-2.5.5.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43810"/>
      <state state_ref="oval:org.mitre.oval:ste:38295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139864" version="1" comment="java-1.7.0-openjdk-debuginfo is earlier than 1:1.7.0.79-2.5.5.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43810"/>
      <state state_ref="oval:org.mitre.oval:ste:39208"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139838" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.79-2.5.5.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:38295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139777" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.79-2.5.5.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:39208"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139611" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.79-2.5.5.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:39208"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139588" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.79-2.5.5.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:38295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139561" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.79-2.5.5.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:39208"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139488" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.79-2.5.5.1.el7_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:39208"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139425" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.79-2.5.5.1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:38295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137244" version="2" comment="bind-devel is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137206" version="2" comment="bind-sdb is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137177" version="2" comment="bind-debuginfo is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42594"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137151" version="2" comment="bind-libs is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137146" version="2" comment="bind-utils is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137141" version="2" comment="bind-debuginfo is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42594"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137117" version="2" comment="bind-debuginfo is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42594"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137092" version="2" comment="bind-libs is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137085" version="2" comment="bind-utils is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137052" version="2" comment="bind-sdb is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137048" version="2" comment="bind-sdb-chroot is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43276"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137046" version="2" comment="bind is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137044" version="2" comment="bind-libs-lite is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42827"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137022" version="2" comment="bind-libbind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137013" version="2" comment="bind-devel is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137006" version="2" comment="bind-chroot is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136991" version="2" comment="bind-chroot is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136944" version="2" comment="bind is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136926" version="2" comment="bind-sdb is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136871" version="2" comment="bind-license is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43057"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136841" version="2" comment="bind-libs is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136778" version="2" comment="bind-utils is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136695" version="2" comment="bind-lite-devel is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43139"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136550" version="2" comment="bind is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136436" version="2" comment="bind-devel is earlier than 32:9.9.4-14.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:37633"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136320" version="2" comment="caching-nameserver is earlier than 30:9.3.6-25.P1.el5_11.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:38033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136248" version="2" comment="bind-chroot is earlier than 32:9.8.2-0.30.rc1.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:37698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137388" version="1" comment="jasper-utils is earlier than 0:1.900.1-26.el7_0.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30190"/>
      <state state_ref="oval:org.mitre.oval:ste:37916"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137351" version="1" comment="jasper-debuginfo is earlier than 0:1.900.1-26.el7_0.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42424"/>
      <state state_ref="oval:org.mitre.oval:ste:37916"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137333" version="1" comment="jasper-libs is earlier than 0:1.900.1-26.el7_0.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29982"/>
      <state state_ref="oval:org.mitre.oval:ste:37916"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137323" version="1" comment="jasper-debuginfo is earlier than 0:1.900.1-16.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42424"/>
      <state state_ref="oval:org.mitre.oval:ste:38102"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137294" version="1" comment="jasper-libs is earlier than 0:1.900.1-16.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29982"/>
      <state state_ref="oval:org.mitre.oval:ste:38102"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137282" version="1" comment="jasper-devel is earlier than 0:1.900.1-16.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30186"/>
      <state state_ref="oval:org.mitre.oval:ste:38102"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137205" version="1" comment="jasper is earlier than 0:1.900.1-16.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29898"/>
      <state state_ref="oval:org.mitre.oval:ste:38102"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137067" version="1" comment="jasper is earlier than 0:1.900.1-26.el7_0.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29898"/>
      <state state_ref="oval:org.mitre.oval:ste:37916"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136997" version="1" comment="jasper-utils is earlier than 0:1.900.1-16.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30190"/>
      <state state_ref="oval:org.mitre.oval:ste:38102"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136928" version="1" comment="jasper-devel is earlier than 0:1.900.1-26.el7_0.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30186"/>
      <state state_ref="oval:org.mitre.oval:ste:37916"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137397" version="1" comment="ntp is earlier than 0:4.2.6p5-19.el7.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:37834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137314" version="3" comment="ntpdate is earlier than 0:4.2.6p5-19.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43174"/>
      <state state_ref="oval:org.mitre.oval:ste:37952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137309" version="1" comment="ntp is earlier than 0:4.2.6p5-2.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:37980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137290" version="1" comment="sntp is earlier than 0:4.2.6p5-19.el7.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43088"/>
      <state state_ref="oval:org.mitre.oval:ste:37834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137270" version="3" comment="sntp is earlier than 0:4.2.6p5-19.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43088"/>
      <state state_ref="oval:org.mitre.oval:ste:37952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137233" version="1" comment="ntp-doc is earlier than 0:4.2.6p5-19.el7.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41911"/>
      <state state_ref="oval:org.mitre.oval:ste:37834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137210" version="3" comment="ntp-doc is earlier than 0:4.2.6p5-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41911"/>
      <state state_ref="oval:org.mitre.oval:ste:37920"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137187" version="1" comment="ntp-doc is earlier than 0:4.2.6p5-2.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41911"/>
      <state state_ref="oval:org.mitre.oval:ste:37980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137163" version="1" comment="ntpdate is earlier than 0:4.2.6p5-19.el7.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43174"/>
      <state state_ref="oval:org.mitre.oval:ste:37834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137149" version="1" comment="ntp-perl is earlier than 0:4.2.6p5-2.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42796"/>
      <state state_ref="oval:org.mitre.oval:ste:37980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137136" version="1" comment="ntpdate is earlier than 0:4.2.6p5-2.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43174"/>
      <state state_ref="oval:org.mitre.oval:ste:37980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137045" version="3" comment="ntp-perl is earlier than 0:4.2.6p5-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42796"/>
      <state state_ref="oval:org.mitre.oval:ste:37920"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137040" version="3" comment="ntp-debuginfo is earlier than 0:4.2.6p5-19.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42942"/>
      <state state_ref="oval:org.mitre.oval:ste:37952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137000" version="3" comment="ntp-doc is earlier than 0:4.2.6p5-19.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41911"/>
      <state state_ref="oval:org.mitre.oval:ste:37952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136989" version="3" comment="ntp is earlier than 0:4.2.6p5-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:37920"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136945" version="3" comment="ntp-debuginfo is earlier than 0:4.2.6p5-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42942"/>
      <state state_ref="oval:org.mitre.oval:ste:37920"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136943" version="1" comment="ntp-perl is earlier than 0:4.2.6p5-19.el7.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42796"/>
      <state state_ref="oval:org.mitre.oval:ste:37834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136869" version="3" comment="ntpdate is earlier than 0:4.2.6p5-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43174"/>
      <state state_ref="oval:org.mitre.oval:ste:37920"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136400" version="3" comment="ntp-perl is earlier than 0:4.2.6p5-19.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42796"/>
      <state state_ref="oval:org.mitre.oval:ste:37952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136291" version="3" comment="ntp is earlier than 0:4.2.6p5-19.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14371"/>
      <state state_ref="oval:org.mitre.oval:ste:37952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136206" version="1" comment="thunderbird is earlier than 0:31.3.0-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:37600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136134" version="1" comment="thunderbird is earlier than 0:31.3.0-1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:37692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136131" version="1" comment="thunderbird-debuginfo is earlier than 0:31.3.0-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43263"/>
      <state state_ref="oval:org.mitre.oval:ste:37600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135999" version="1" comment="thunderbird is earlier than 0:31.3.0-1.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:37781"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135692" version="1" comment="thunderbird-debuginfo is earlier than 0:31.3.0-1.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43263"/>
      <state state_ref="oval:org.mitre.oval:ste:37692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135513" version="1" comment="thunderbird is earlier than 0:31.3.0-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:37863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139017" version="1" comment="openssl-debuginfo is earlier than 0:1.0.1e-30.el6_6.11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43044"/>
      <state state_ref="oval:org.mitre.oval:ste:38917"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:139010" version="1" comment="openssl-libs is earlier than 1:1.0.1e-42.el7_1.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42399"/>
      <state state_ref="oval:org.mitre.oval:ste:38782"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138987" version="1" comment="openssl-debuginfo is earlier than 1:1.0.1e-42.el7_1.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43044"/>
      <state state_ref="oval:org.mitre.oval:ste:38782"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138952" version="1" comment="openssl-devel is earlier than 1:1.0.1e-42.el7_1.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41966"/>
      <state state_ref="oval:org.mitre.oval:ste:38782"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138947" version="1" comment="openssl is earlier than 1:1.0.1e-42.el7_1.8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30443"/>
      <state state_ref="oval:org.mitre.oval:ste:38782"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138540" version="1" comment="openssl-devel is earlier than 0:1.0.1e-30.el6_6.11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41966"/>
      <state state_ref="oval:org.mitre.oval:ste:38917"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138175" version="1" comment="openssl is earlier than 0:1.0.1e-30.el6_6.11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30443"/>
      <state state_ref="oval:org.mitre.oval:ste:38917"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137736" version="1" comment="glibc-utils is earlier than 0:2.12-1.149.el6_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:38083"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137730" version="1" comment="glibc-debuginfo-common is earlier than 0:2.17-55.el7_0.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42178"/>
      <state state_ref="oval:org.mitre.oval:ste:38205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137698" version="1" comment="glibc is earlier than 0:2.17-55.el7_0.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:38205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137687" version="1" comment="glibc-debuginfo is earlier than 0:2.12-1.149.el6_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4398"/>
      <state state_ref="oval:org.mitre.oval:ste:38083"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137634" version="1" comment="glibc is earlier than 0:2.12-1.149.el6_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:38083"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137602" version="1" comment="glibc-common is earlier than 0:2.12-1.149.el6_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:38083"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137589" version="1" comment="glibc-debuginfo is earlier than 0:2.17-55.el7_0.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4398"/>
      <state state_ref="oval:org.mitre.oval:ste:38205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137562" version="1" comment="glibc-devel is earlier than 0:2.17-55.el7_0.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:38205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137554" version="1" comment="glibc-common is earlier than 0:2.17-55.el7_0.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:38205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137544" version="1" comment="glibc-headers is earlier than 0:2.17-55.el7_0.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:38205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137540" version="1" comment="nscd is earlier than 0:2.17-55.el7_0.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:38205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137296" version="1" comment="glibc-debuginfo-common is earlier than 0:2.12-1.149.el6_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42178"/>
      <state state_ref="oval:org.mitre.oval:ste:38083"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137283" version="1" comment="glibc-utils is earlier than 0:2.17-55.el7_0.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:38205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137192" version="1" comment="nscd is earlier than 0:2.12-1.149.el6_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:38083"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137079" version="1" comment="glibc-headers is earlier than 0:2.12-1.149.el6_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:38083"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137023" version="1" comment="glibc-static is earlier than 0:2.12-1.149.el6_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30224"/>
      <state state_ref="oval:org.mitre.oval:ste:38083"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136859" version="1" comment="glibc-static is earlier than 0:2.17-55.el7_0.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30224"/>
      <state state_ref="oval:org.mitre.oval:ste:38205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136840" version="1" comment="glibc-devel is earlier than 0:2.12-1.149.el6_6.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:38083"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136177" version="1" comment="libXfont is earlier than 0:1.4.5-4.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14504"/>
      <state state_ref="oval:org.mitre.oval:ste:36903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136081" version="1" comment="libXfont-devel is earlier than 0:1.4.5-4.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14538"/>
      <state state_ref="oval:org.mitre.oval:ste:36903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136011" version="1" comment="libXfont is earlier than 0:1.4.7-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14504"/>
      <state state_ref="oval:org.mitre.oval:ste:37301"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136003" version="1" comment="libXfont-devel is earlier than 0:1.4.7-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14538"/>
      <state state_ref="oval:org.mitre.oval:ste:37301"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135927" version="1" comment="libXfont-debuginfo is earlier than 0:1.4.5-4.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43247"/>
      <state state_ref="oval:org.mitre.oval:ste:36903"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135699" version="1" comment="libXfont-debuginfo is earlier than 0:1.4.7-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43247"/>
      <state state_ref="oval:org.mitre.oval:ste:37301"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137320" version="1" comment="mailx-debuginfo is earlier than 0:12.4-8.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42903"/>
      <state state_ref="oval:org.mitre.oval:ste:37884"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137183" version="1" comment="mailx-debuginfo is earlier than 0:12.5-12.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42903"/>
      <state state_ref="oval:org.mitre.oval:ste:38066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137098" version="1" comment="mailx is earlier than 0:12.4-8.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39974"/>
      <state state_ref="oval:org.mitre.oval:ste:37884"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136842" version="1" comment="mailx is earlier than 0:12.5-12.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39974"/>
      <state state_ref="oval:org.mitre.oval:ste:38066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136268" version="1" comment="mod_auth_mellon-debuginfo is earlier than 0:0.8.0-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43273"/>
      <state state_ref="oval:org.mitre.oval:ste:37854"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136247" version="1" comment="mod_auth_mellon is earlier than 0:0.8.0-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43041"/>
      <state state_ref="oval:org.mitre.oval:ste:37854"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136313" version="1" comment="wget is earlier than 0:1.12-5.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14591"/>
      <state state_ref="oval:org.mitre.oval:ste:37648"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136001" version="1" comment="wget is earlier than 0:1.14-10.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14591"/>
      <state state_ref="oval:org.mitre.oval:ste:37820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135985" version="1" comment="wget-debuginfo is earlier than 0:1.12-5.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43231"/>
      <state state_ref="oval:org.mitre.oval:ste:37648"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135430" version="1" comment="wget-debuginfo is earlier than 0:1.14-10.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43231"/>
      <state state_ref="oval:org.mitre.oval:ste:37820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136270" version="1" comment="libvirt-python is earlier than 0:0.10.2-46.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15191"/>
      <state state_ref="oval:org.mitre.oval:ste:37845"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136245" version="1" comment="libvirt-lock-sanlock is earlier than 0:0.10.2-46.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28971"/>
      <state state_ref="oval:org.mitre.oval:ste:37845"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136112" version="1" comment="libvirt is earlier than 0:0.10.2-46.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15209"/>
      <state state_ref="oval:org.mitre.oval:ste:37845"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136088" version="1" comment="libvirt-client is earlier than 0:0.10.2-46.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29031"/>
      <state state_ref="oval:org.mitre.oval:ste:37845"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136082" version="1" comment="libvirt-debuginfo is earlier than 0:0.10.2-46.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43109"/>
      <state state_ref="oval:org.mitre.oval:ste:37845"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135935" version="1" comment="libvirt-devel is earlier than 0:0.10.2-46.el6_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14880"/>
      <state state_ref="oval:org.mitre.oval:ste:37845"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136251" version="1" comment="libvncserver-debuginfo is earlier than 0:0.9.9-9.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42695"/>
      <state state_ref="oval:org.mitre.oval:ste:37560"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136094" version="1" comment="libvncserver is earlier than 0:0.9.7-7.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42763"/>
      <state state_ref="oval:org.mitre.oval:ste:37761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136073" version="1" comment="libvncserver-devel is earlier than 0:0.9.9-9.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42859"/>
      <state state_ref="oval:org.mitre.oval:ste:37560"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135723" version="1" comment="libvncserver-devel is earlier than 0:0.9.7-7.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42859"/>
      <state state_ref="oval:org.mitre.oval:ste:37761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135437" version="1" comment="libvncserver-debuginfo is earlier than 0:0.9.7-7.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42695"/>
      <state state_ref="oval:org.mitre.oval:ste:37761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135403" version="1" comment="libvncserver is earlier than 0:0.9.9-9.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42763"/>
      <state state_ref="oval:org.mitre.oval:ste:37560"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136240" version="1" comment="ruby-static is earlier than 0:1.8.7.374-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28990"/>
      <state state_ref="oval:org.mitre.oval:ste:37270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136238" version="1" comment="ruby-irb is earlier than 0:1.8.7.374-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14777"/>
      <state state_ref="oval:org.mitre.oval:ste:37270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136229" version="1" comment="ruby-rdoc is earlier than 0:1.8.7.374-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14244"/>
      <state state_ref="oval:org.mitre.oval:ste:37270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136222" version="1" comment="ruby-libs is earlier than 0:1.8.7.374-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:37270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136126" version="1" comment="ruby-tcltk is earlier than 0:1.8.7.374-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:37270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136110" version="1" comment="ruby-devel is earlier than 0:1.8.7.374-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:37270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135988" version="1" comment="ruby-ri is earlier than 0:1.8.7.374-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14461"/>
      <state state_ref="oval:org.mitre.oval:ste:37270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135972" version="1" comment="ruby-docs is earlier than 0:1.8.7.374-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:37270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135837" version="1" comment="ruby is earlier than 0:1.8.7.374-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:37270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135732" version="1" comment="ruby-debuginfo is earlier than 0:1.8.7.374-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42519"/>
      <state state_ref="oval:org.mitre.oval:ste:37270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136207" version="1" comment="nss-util-debuginfo is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42869"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136106" version="1" comment="nss-util-debuginfo is earlier than 0:3.16.2.3-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42869"/>
      <state state_ref="oval:org.mitre.oval:ste:37481"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136093" version="1" comment="nss-softokn-devel is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29485"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136085" version="1" comment="nss-softokn-debuginfo is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43053"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136083" version="1" comment="nss-tools is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136072" version="1" comment="nss-sysinit is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136065" version="1" comment="nss-util-devel is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136054" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:37644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136049" version="1" comment="nss-util is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136028" version="1" comment="nss-debuginfo is earlier than 0:3.16.2.3-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135977" version="1" comment="nss is earlier than 0:3.16.2.3-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:37644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135957" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135941" version="1" comment="nss-softokn is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29421"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135936" version="1" comment="nss-debuginfo is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135877" version="1" comment="nss-util-devel is earlier than 0:3.16.2.3-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:37481"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135854" version="1" comment="nss-tools is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135848" version="1" comment="nss-devel is earlier than 0:3.16.2.3-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:37644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135797" version="1" comment="nss-softokn-freebl is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29159"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135785" version="1" comment="nss is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135718" version="1" comment="nss-devel is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135709" version="1" comment="nss-sysinit is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135679" version="1" comment="nss-softokn-freebl-devel is earlier than 0:3.16.2.3-1.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29515"/>
      <state state_ref="oval:org.mitre.oval:ste:37666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135637" version="1" comment="nss-tools is earlier than 0:3.16.2.3-1.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:37644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135612" version="1" comment="nss-devel is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135216" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135157" version="1" comment="nss is earlier than 0:3.16.2.3-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:37825"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135108" version="1" comment="nss-debuginfo is earlier than 0:3.16.2.3-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37821"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135104" version="1" comment="nss-util is earlier than 0:3.16.2.3-2.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:37481"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136318" version="1" comment="php-xml is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136316" version="1" comment="php-xmlrpc is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136305" version="1" comment="php-gd is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136287" version="1" comment="php-soap is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136266" version="1" comment="php is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136260" version="1" comment="php-tidy is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28881"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136252" version="1" comment="php-mbstring is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136225" version="1" comment="php-recode is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136221" version="1" comment="php-zts is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29304"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136208" version="1" comment="php-pdo is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136198" version="1" comment="php-process is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136195" version="1" comment="php-odbc is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136191" version="1" comment="php-xml is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136186" version="1" comment="php is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136184" version="1" comment="php-intl is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136172" version="1" comment="php-pgsql is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136167" version="1" comment="php-gd is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136163" version="1" comment="php-xmlrpc is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136158" version="1" comment="php-embedded is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136128" version="1" comment="php-snmp is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136122" version="1" comment="php-mysql is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136119" version="1" comment="php-mbstring is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136113" version="1" comment="php-fpm is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29228"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136101" version="1" comment="php-pspell is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136099" version="1" comment="php-common is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136079" version="1" comment="php-enchant is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136066" version="1" comment="php-devel is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136064" version="1" comment="php-process is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136063" version="1" comment="php-bcmath is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136055" version="1" comment="php-debuginfo is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42299"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136048" version="1" comment="php-pspell is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136039" version="1" comment="php-bcmath is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136026" version="1" comment="php-enchant is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136018" version="1" comment="php-dba is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135993" version="1" comment="php-soap is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135989" version="1" comment="php-devel is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135975" version="1" comment="php-fpm is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29228"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135971" version="1" comment="php-odbc is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135958" version="1" comment="php-ldap is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135953" version="1" comment="php-intl is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135950" version="1" comment="php-imap is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135948" version="1" comment="php-embedded is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135944" version="1" comment="php-recode is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135894" version="1" comment="php-cli is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135839" version="1" comment="php-snmp is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135803" version="1" comment="php-mysql is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135796" version="1" comment="php-ldap is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135775" version="1" comment="php-dba is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135760" version="1" comment="php-pdo is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135739" version="1" comment="php-pgsql is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135736" version="1" comment="php-common is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135608" version="1" comment="php-cli is earlier than 0:5.3.3-40.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:37416"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135516" version="1" comment="php-mysqlnd is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42002"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135404" version="1" comment="php-debuginfo is earlier than 0:5.4.16-23.el7_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42299"/>
      <state state_ref="oval:org.mitre.oval:ste:37361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136297" version="1" comment="kernel-debug is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136293" version="1" comment="kernel-debuginfo is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42117"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136271" version="1" comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42704"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136262" version="1" comment="python-perf is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136255" version="1" comment="kernel-firmware is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136204" version="1" comment="kernel-doc is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136130" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136109" version="1" comment="kernel-debuginfo-common-i686 is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42774"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136062" version="1" comment="kernel-headers is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135969" version="1" comment="kernel-debug-debuginfo is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42590"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135815" version="1" comment="kernel is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135807" version="1" comment="perf-debuginfo is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42724"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135672" version="1" comment="kernel-abi-whitelists is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29639"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135517" version="1" comment="kernel-devel is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135456" version="1" comment="perf is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135326" version="1" comment="python-perf-debuginfo is earlier than 0:2.6.32-504.1.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43043"/>
      <state state_ref="oval:org.mitre.oval:ste:37740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136031" version="1" comment="firefox is earlier than 0:31.3.0-3.el7.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37729"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135966" version="1" comment="firefox is earlier than 0:31.3.0-4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135952" version="1" comment="firefox is earlier than 0:31.3.0-3.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37770"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135920" version="1" comment="firefox-debuginfo is earlier than 0:31.3.0-4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43227"/>
      <state state_ref="oval:org.mitre.oval:ste:37610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135768" version="1" comment="firefox-debuginfo is earlier than 0:31.3.0-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43227"/>
      <state state_ref="oval:org.mitre.oval:ste:37777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135742" version="1" comment="firefox is earlier than 0:31.3.0-4.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37492"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135687" version="1" comment="firefox is earlier than 0:31.3.0-3.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37535"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135624" version="1" comment="firefox is earlier than 0:31.3.0-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135350" version="1" comment="firefox-debuginfo is earlier than 0:31.3.0-3.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43227"/>
      <state state_ref="oval:org.mitre.oval:ste:37770"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137400" version="1" comment="kernel-abi-whitelists is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29639"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137348" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137336" version="1" comment="kernel is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137305" version="1" comment="kernel-doc is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137297" version="1" comment="kernel-debuginfo-common-i686 is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42774"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137259" version="1" comment="kernel-firmware is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137209" version="1" comment="kernel-debuginfo is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42117"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137194" version="1" comment="perf is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137082" version="1" comment="python-perf-debuginfo is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43043"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137043" version="1" comment="python-perf is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137008" version="1" comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42704"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136990" version="1" comment="kernel-debug is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136976" version="1" comment="kernel-headers is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136957" version="1" comment="kernel-debug-debuginfo is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42590"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136931" version="1" comment="perf-debuginfo is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42724"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136848" version="1" comment="kernel-devel is earlier than 0:2.6.32-504.3.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:37780"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125893" version="1" comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-12.7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14775"/>
      <state state_ref="oval:org.mitre.oval:ste:34541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125840" version="1" comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-12.7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14818"/>
      <state state_ref="oval:org.mitre.oval:ste:34541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125837" version="1" comment="xerces-j2-scripts is earlier than 0:2.7.1-12.7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14314"/>
      <state state_ref="oval:org.mitre.oval:ste:34541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125812" version="1" comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-12.7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14948"/>
      <state state_ref="oval:org.mitre.oval:ste:34541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125800" version="1" comment="xerces-j2-demo is earlier than 0:2.11.0-17.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15310"/>
      <state state_ref="oval:org.mitre.oval:ste:34676"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125796" version="1" comment="xerces-j2-javadoc is earlier than 0:2.11.0-17.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42180"/>
      <state state_ref="oval:org.mitre.oval:ste:34676"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125678" version="1" comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-12.7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15179"/>
      <state state_ref="oval:org.mitre.oval:ste:34541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125674" version="1" comment="xerces-j2 is earlier than 0:2.11.0-17.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15189"/>
      <state state_ref="oval:org.mitre.oval:ste:34676"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125521" version="1" comment="xerces-j2-demo is earlier than 0:2.7.1-12.7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15310"/>
      <state state_ref="oval:org.mitre.oval:ste:34541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124920" version="1" comment="xerces-j2 is earlier than 0:2.7.1-12.7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15189"/>
      <state state_ref="oval:org.mitre.oval:ste:34541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126223" version="1" comment="perf-debuginfo is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42724"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126189" version="1" comment="python-perf is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126159" version="1" comment="kernel-firmware is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126135" version="1" comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42704"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126125" version="1" comment="kernel-debug is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126110" version="1" comment="kernel-debuginfo-common-i686 is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42774"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126072" version="1" comment="kernel is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126053" version="1" comment="kernel-debug-debuginfo is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42590"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126013" version="1" comment="kernel-debuginfo is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42117"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125887" version="1" comment="kernel-devel is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125698" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125342" version="1" comment="kernel-doc is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125281" version="1" comment="perf is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125227" version="1" comment="kernel-headers is earlier than 0:2.6.32-220.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:34053"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126144" version="1" comment="ocaml-libguestfs is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29314"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126120" version="1" comment="libguestfs is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30138"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126065" version="1" comment="ruby-libguestfs is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29776"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126057" version="1" comment="libguestfs-debuginfo is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42502"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126005" version="1" comment="libguestfs-tools-c is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29928"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125999" version="1" comment="libguestfs-tools is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29734"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125965" version="1" comment="ocaml-libguestfs-devel is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29979"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125959" version="1" comment="libguestfs-java is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30086"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125934" version="1" comment="libguestfs-devel is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30024"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125648" version="1" comment="perl-Sys-Guestfs is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29983"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125536" version="1" comment="python-libguestfs is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30098"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125285" version="1" comment="libguestfs-java-devel is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30244"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125158" version="1" comment="libguestfs-javadoc is earlier than 0:1.20.11-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30167"/>
      <state state_ref="oval:org.mitre.oval:ste:35007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126172" version="1" comment="qemu-kvm is earlier than 0:0.12.1.2-2.415.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29139"/>
      <state state_ref="oval:org.mitre.oval:ste:34662"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126170" version="1" comment="qemu-img is earlier than 0:0.12.1.2-2.415.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29180"/>
      <state state_ref="oval:org.mitre.oval:ste:34662"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126102" version="1" comment="qemu-guest-agent is earlier than 0:0.12.1.2-2.415.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28988"/>
      <state state_ref="oval:org.mitre.oval:ste:34662"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125985" version="1" comment="qemu-kvm-tools is earlier than 0:0.12.1.2-2.415.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:34662"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125968" version="1" comment="qemu-kvm-debuginfo is earlier than 0:0.12.1.2-2.415.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42615"/>
      <state state_ref="oval:org.mitre.oval:ste:34662"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126255" version="1" comment="libcap-devel is earlier than 0:2.16-5.5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41840"/>
      <state state_ref="oval:org.mitre.oval:ste:34637"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125836" version="1" comment="libcap is earlier than 0:2.16-5.5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42637"/>
      <state state_ref="oval:org.mitre.oval:ste:34637"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125476" version="1" comment="libcap-debuginfo is earlier than 0:2.16-5.5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42733"/>
      <state state_ref="oval:org.mitre.oval:ste:34637"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125920" version="1" comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125911" version="1" comment="php53-process is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29375"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125902" version="1" comment="php53-pspell is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29208"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125900" version="1" comment="php-zts is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29304"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125888" version="1" comment="php-imap is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125886" version="1" comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125877" version="1" comment="php53-pdo is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29253"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125873" version="1" comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125832" version="1" comment="php-dba is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125814" version="1" comment="php-pdo is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125813" version="1" comment="php-process is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125784" version="1" comment="php53-intl is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29195"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125778" version="1" comment="php-enchant is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125746" version="1" comment="php-snmp is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125741" version="1" comment="php53-ldap is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29602"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125739" version="1" comment="php53-dba is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28950"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125738" version="1" comment="php-mysql is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125724" version="1" comment="php53-common is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29562"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125711" version="1" comment="php53-devel is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29547"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125705" version="1" comment="php53-soap is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29455"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125697" version="1" comment="php-xml is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125683" version="1" comment="php-ldap is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125661" version="1" comment="php-recode is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125654" version="1" comment="php-intl is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125644" version="1" comment="php-fpm is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29228"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125640" version="1" comment="php53-xmlrpc is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29475"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125620" version="1" comment="php-odbc is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125614" version="1" comment="php-tidy is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28881"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125520" version="1" comment="php53-imap is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29568"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125519" version="1" comment="php53-mysql is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29022"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125516" version="1" comment="php53-pgsql is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29505"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125507" version="1" comment="php-pspell is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125496" version="1" comment="php53 is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29556"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125461" version="1" comment="php53-cli is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28902"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125455" version="1" comment="php53-odbc is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29337"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125414" version="1" comment="php-cli is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125409" version="1" comment="php is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125406" version="1" comment="php-soap is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125361" version="1" comment="php-common is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125184" version="1" comment="php53-gd is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29626"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125177" version="1" comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125173" version="1" comment="php53-mbstring is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29008"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125124" version="1" comment="php-devel is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125105" version="1" comment="php53-xml is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29235"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125033" version="1" comment="php-gd is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125011" version="1" comment="php53-snmp is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29427"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124972" version="1" comment="php-embedded is earlier than 0:5.3.3-27.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:34965"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124943" version="1" comment="php53-bcmath is earlier than 0:5.3.3-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29087"/>
      <state state_ref="oval:org.mitre.oval:ste:34882"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126109" version="1" comment="libibverbs-debuginfo is earlier than 0:1.1.7-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42451"/>
      <state state_ref="oval:org.mitre.oval:ste:34761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126103" version="1" comment="infinipath-psm-devel is earlier than 0:3.0.1-115.1015_open.2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29267"/>
      <state state_ref="oval:org.mitre.oval:ste:34775"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126079" version="1" comment="libibverbs-devel-static is earlier than 0:1.1.7-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29246"/>
      <state state_ref="oval:org.mitre.oval:ste:34761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126062" version="1" comment="openmpi is earlier than 0:1.5.4-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42680"/>
      <state state_ref="oval:org.mitre.oval:ste:34689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126060" version="1" comment="mpitests-mvapich-psm is earlier than 0:3.2-9.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42612"/>
      <state state_ref="oval:org.mitre.oval:ste:34585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126047" version="1" comment="ibutils-debuginfo is earlier than 0:1.5.7-8.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42332"/>
      <state state_ref="oval:org.mitre.oval:ste:34736"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126045" version="1" comment="ibutils-devel is earlier than 0:1.5.7-8.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29122"/>
      <state state_ref="oval:org.mitre.oval:ste:34736"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126038" version="1" comment="qperf is earlier than 0:0.4.9-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42589"/>
      <state state_ref="oval:org.mitre.oval:ste:34668"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126023" version="1" comment="librdmacm-debuginfo is earlier than 0:1.0.17-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42333"/>
      <state state_ref="oval:org.mitre.oval:ste:34849"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126021" version="1" comment="libmlx4-static is earlier than 0:1.0.5-4.el6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29331"/>
      <state state_ref="oval:org.mitre.oval:ste:34515"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126020" version="1" comment="librdmacm-utils is earlier than 0:1.0.17-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29223"/>
      <state state_ref="oval:org.mitre.oval:ste:34849"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126001" version="1" comment="librdmacm-static is earlier than 0:1.0.17-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28625"/>
      <state state_ref="oval:org.mitre.oval:ste:34849"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126000" version="1" comment="openmpi-debuginfo is earlier than 0:1.5.4-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42639"/>
      <state state_ref="oval:org.mitre.oval:ste:34689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125993" version="1" comment="qperf-debuginfo is earlier than 0:0.4.9-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42529"/>
      <state state_ref="oval:org.mitre.oval:ste:34668"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125990" version="1" comment="openmpi-devel is earlier than 0:1.5.4-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42710"/>
      <state state_ref="oval:org.mitre.oval:ste:34689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125966" version="1" comment="libmlx4 is earlier than 0:1.0.5-4.el6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29176"/>
      <state state_ref="oval:org.mitre.oval:ste:34515"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125952" version="1" comment="mpitests-mvapich2 is earlier than 0:3.2-9.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42372"/>
      <state state_ref="oval:org.mitre.oval:ste:34585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125948" version="1" comment="mpitests-mvapich is earlier than 0:3.2-9.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42690"/>
      <state state_ref="oval:org.mitre.oval:ste:34585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125946" version="1" comment="mpitests-openmpi is earlier than 0:3.2-9.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42610"/>
      <state state_ref="oval:org.mitre.oval:ste:34585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125945" version="1" comment="ibutils-libs is earlier than 0:1.5.7-8.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29282"/>
      <state state_ref="oval:org.mitre.oval:ste:34736"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125942" version="1" comment="mpitests-debuginfo is earlier than 0:3.2-9.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42118"/>
      <state state_ref="oval:org.mitre.oval:ste:34585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125914" version="1" comment="librdmacm-devel is earlier than 0:1.0.17-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29326"/>
      <state state_ref="oval:org.mitre.oval:ste:34849"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125856" version="1" comment="perftest is earlier than 0:2.0-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42365"/>
      <state state_ref="oval:org.mitre.oval:ste:34571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125817" version="1" comment="librdmacm is earlier than 0:1.0.17-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29075"/>
      <state state_ref="oval:org.mitre.oval:ste:34849"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125787" version="1" comment="libibverbs is earlier than 0:1.1.7-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28888"/>
      <state state_ref="oval:org.mitre.oval:ste:34761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125783" version="1" comment="libibverbs-devel is earlier than 0:1.1.7-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29297"/>
      <state state_ref="oval:org.mitre.oval:ste:34761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125747" version="1" comment="rdma is earlier than 0:3.10-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29056"/>
      <state state_ref="oval:org.mitre.oval:ste:34592"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125542" version="1" comment="ibutils is earlier than 0:1.5.7-8.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29301"/>
      <state state_ref="oval:org.mitre.oval:ste:34736"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125513" version="1" comment="infinipath-psm is earlier than 0:3.0.1-115.1015_open.2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28985"/>
      <state state_ref="oval:org.mitre.oval:ste:34775"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125494" version="1" comment="perftest-debuginfo is earlier than 0:2.0-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42645"/>
      <state state_ref="oval:org.mitre.oval:ste:34571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125463" version="1" comment="libibverbs-utils is earlier than 0:1.1.7-1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29193"/>
      <state state_ref="oval:org.mitre.oval:ste:34761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125324" version="1" comment="libmlx4-debuginfo is earlier than 0:1.0.5-4.el6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42734"/>
      <state state_ref="oval:org.mitre.oval:ste:34515"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125171" version="1" comment="mpitests-mvapich2-psm is earlier than 0:3.2-9.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42236"/>
      <state state_ref="oval:org.mitre.oval:ste:34585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125390" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:34728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125380" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:34739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125374" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.33-1.13.5.0.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:34257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125373" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:34728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125310" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:34728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125277" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:34739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125226" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:34257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125224" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:34728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125213" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.33-1.13.5.0.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:34257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125204" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:34739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125178" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.33-1.13.5.0.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:34739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125149" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:34728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125061" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:34739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124735" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.33-1.13.5.0.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:34257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124654" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.33-1.13.5.0.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:34257"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126181" version="1" comment="kdelibs-common is earlier than 0:4.3.4-14.el6_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30277"/>
      <state state_ref="oval:org.mitre.oval:ste:34979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126142" version="1" comment="kdelibs-apidocs is earlier than 0:4.3.4-14.el6_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15138"/>
      <state state_ref="oval:org.mitre.oval:ste:34979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126087" version="1" comment="kdelibs-debuginfo is earlier than 0:4.3.4-14.el6_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42632"/>
      <state state_ref="oval:org.mitre.oval:ste:34979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126037" version="1" comment="kdelibs is earlier than 0:4.3.4-14.el6_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:34979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125190" version="1" comment="kdelibs-devel is earlier than 0:4.3.4-14.el6_3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:34979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126107" version="1" comment="389-ds-base is earlier than 0:1.2.11.15-30.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28953"/>
      <state state_ref="oval:org.mitre.oval:ste:34776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126081" version="1" comment="389-ds-base-libs is earlier than 0:1.2.11.15-30.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28949"/>
      <state state_ref="oval:org.mitre.oval:ste:34776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125962" version="1" comment="389-ds-base-devel is earlier than 0:1.2.11.15-30.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29162"/>
      <state state_ref="oval:org.mitre.oval:ste:34776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125586" version="1" comment="389-ds-base-debuginfo is earlier than 0:1.2.11.15-30.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42694"/>
      <state state_ref="oval:org.mitre.oval:ste:34776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126267" version="1" comment="kexec-tools-debuginfo is earlier than 0:2.0.0-209.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42737"/>
      <state state_ref="oval:org.mitre.oval:ste:34710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126084" version="1" comment="kexec-tools is earlier than 0:2.0.0-209.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29363"/>
      <state state_ref="oval:org.mitre.oval:ste:34710"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125377" version="1" comment="java-1.7.0-openjdk-headless is earlier than 1:1.7.0.71-2.5.3.1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38823"/>
      <state state_ref="oval:org.mitre.oval:ste:34748"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125321" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.71-2.5.3.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:34643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125320" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.71-2.5.3.1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:34748"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125317" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.71-2.5.3.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:34643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125316" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.71-2.5.3.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:34643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125278" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.71-2.5.3.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:34643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125262" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.71-2.5.3.1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:34748"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125261" version="1" comment="java-1.7.0-openjdk-accessibility is earlier than 1:1.7.0.71-2.5.3.1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39184"/>
      <state state_ref="oval:org.mitre.oval:ste:34748"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125216" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.71-2.5.3.1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:34748"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125050" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.71-2.5.3.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:34643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125035" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.71-2.5.3.1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:34748"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124961" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.71-2.5.3.1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:34748"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138154" version="1" comment="libxml2-debuginfo is earlier than 0:2.7.6-17.el6_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42511"/>
      <state state_ref="oval:org.mitre.oval:ste:38552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138130" version="1" comment="libxml2-debuginfo is earlier than 0:2.9.1-5.el7_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42511"/>
      <state state_ref="oval:org.mitre.oval:ste:38549"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125403" version="1" comment="libxml2 is earlier than 0:2.9.1-5.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:34771"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125333" version="1" comment="libxml2-static is earlier than 0:2.7.6-17.el6_6.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28876"/>
      <state state_ref="oval:org.mitre.oval:ste:34550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125267" version="1" comment="libxml2 is earlier than 0:2.7.6-17.el6_6.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:34550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125241" version="1" comment="libxml2-python is earlier than 0:2.9.1-5.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:34771"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125229" version="1" comment="libxml2-devel is earlier than 0:2.9.1-5.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:34771"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125130" version="1" comment="libxml2-static is earlier than 0:2.9.1-5.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28876"/>
      <state state_ref="oval:org.mitre.oval:ste:34771"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125031" version="1" comment="libxml2-python is earlier than 0:2.7.6-17.el6_6.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:34550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124790" version="1" comment="libxml2-devel is earlier than 0:2.7.6-17.el6_6.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:34550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126278" version="1" comment="libxml2-static is earlier than 0:2.7.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28876"/>
      <state state_ref="oval:org.mitre.oval:ste:35050"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126231" version="1" comment="libxml2-debuginfo is earlier than 0:2.7.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42511"/>
      <state state_ref="oval:org.mitre.oval:ste:35050"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126157" version="1" comment="libxml2-python is earlier than 0:2.7.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:35050"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126052" version="1" comment="libxml2-devel is earlier than 0:2.7.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:35050"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125769" version="1" comment="libxml2 is earlier than 0:2.7.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:35050"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125259" version="1" comment="thunderbird is earlier than 0:31.2.0-2.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:34711"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125147" version="1" comment="thunderbird is earlier than 0:31.2.0-2.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:34226"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125043" version="1" comment="thunderbird is earlier than 0:31.2.0-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:34569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125165" version="1" comment="chromium-browser is earlier than 0:38.0.2125.101-2.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42487"/>
      <state state_ref="oval:org.mitre.oval:ste:34384"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126317" version="1" comment="kdelibs-devel is earlier than 0:4.3.4-11.el6_1.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:34858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126230" version="1" comment="kdelibs-common is earlier than 0:4.3.4-11.el6_1.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30277"/>
      <state state_ref="oval:org.mitre.oval:ste:34858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126191" version="1" comment="kdelibs-debuginfo is earlier than 0:4.3.4-11.el6_1.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42632"/>
      <state state_ref="oval:org.mitre.oval:ste:34858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126007" version="1" comment="kdelibs is earlier than 0:4.3.4-11.el6_1.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:34858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125982" version="1" comment="kdelibs-apidocs is earlier than 0:4.3.4-11.el6_1.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15138"/>
      <state state_ref="oval:org.mitre.oval:ste:34858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126108" version="1" comment="control-center-filesystem is earlier than 0:2.28.1-39.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42723"/>
      <state state_ref="oval:org.mitre.oval:ste:34034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126104" version="1" comment="gnome-panel-debuginfo is earlier than 0:2.30.2-15.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:5226"/>
      <state state_ref="oval:org.mitre.oval:ste:34557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126085" version="1" comment="evolution-data-server-debuginfo is earlier than 0:2.32.3-18.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4343"/>
      <state state_ref="oval:org.mitre.oval:ste:34798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126075" version="1" comment="planner-eds is earlier than 0:0.14.4-10.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42326"/>
      <state state_ref="oval:org.mitre.oval:ste:34374"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126073" version="1" comment="evolution-exchange is earlier than 0:2.32.3-16.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3389"/>
      <state state_ref="oval:org.mitre.oval:ste:34898"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126069" version="1" comment="gnome-python2-libgtop2 is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42486"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126063" version="1" comment="evolution-mapi-devel is earlier than 0:0.32.2-12.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29204"/>
      <state state_ref="oval:org.mitre.oval:ste:34508"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126059" version="1" comment="control-center-devel is earlier than 0:2.28.1-39.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3336"/>
      <state state_ref="oval:org.mitre.oval:ste:34034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126054" version="1" comment="totem-mozplugin is earlier than 0:2.28.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15001"/>
      <state state_ref="oval:org.mitre.oval:ste:34943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126050" version="1" comment="evolution-mapi is earlier than 0:0.32.2-12.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29098"/>
      <state state_ref="oval:org.mitre.oval:ste:34508"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126049" version="1" comment="gnome-python2-brasero is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41820"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126044" version="1" comment="gnome-panel-devel is earlier than 0:2.30.2-15.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:5142"/>
      <state state_ref="oval:org.mitre.oval:ste:34557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126035" version="1" comment="pidgin-docs is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14724"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126030" version="1" comment="pidgin is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126018" version="1" comment="evolution-devel-docs is earlier than 0:2.32.3-30.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42548"/>
      <state state_ref="oval:org.mitre.oval:ste:34873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126014" version="1" comment="evolution-exchange-debuginfo is earlier than 0:2.32.3-16.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4153"/>
      <state state_ref="oval:org.mitre.oval:ste:34898"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126010" version="1" comment="evolution-data-server-doc is earlier than 0:2.32.3-18.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15054"/>
      <state state_ref="oval:org.mitre.oval:ste:34798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126003" version="1" comment="control-center-debuginfo is earlier than 0:2.28.1-39.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3375"/>
      <state state_ref="oval:org.mitre.oval:ste:34034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125997" version="1" comment="gnome-python2-totem is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42636"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125996" version="1" comment="pidgin-debuginfo is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42670"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125994" version="1" comment="control-center-extra is earlier than 0:2.28.1-39.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42701"/>
      <state state_ref="oval:org.mitre.oval:ste:34034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125992" version="1" comment="gtkhtml3 is earlier than 0:3.32.2-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42466"/>
      <state state_ref="oval:org.mitre.oval:ste:34753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125978" version="1" comment="libgdata-devel is earlier than 0:0.6.4-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42706"/>
      <state state_ref="oval:org.mitre.oval:ste:34863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125975" version="1" comment="evolution is earlier than 0:2.32.3-30.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14477"/>
      <state state_ref="oval:org.mitre.oval:ste:34873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125972" version="1" comment="totem-nautilus is earlier than 0:2.28.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42491"/>
      <state state_ref="oval:org.mitre.oval:ste:34943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125969" version="1" comment="planner is earlier than 0:0.14.4-10.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42698"/>
      <state state_ref="oval:org.mitre.oval:ste:34374"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125967" version="1" comment="evolution-devel is earlier than 0:2.32.3-30.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14585"/>
      <state state_ref="oval:org.mitre.oval:ste:34873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125960" version="1" comment="gtkhtml3-debuginfo is earlier than 0:3.32.2-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42556"/>
      <state state_ref="oval:org.mitre.oval:ste:34753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125957" version="1" comment="pidgin-devel is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125949" version="1" comment="totem-jamendo is earlier than 0:2.28.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42257"/>
      <state state_ref="oval:org.mitre.oval:ste:34943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125939" version="1" comment="gnome-python2-rsvg is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42618"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125935" version="1" comment="gnome-python2-gnomeprint is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41766"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125932" version="1" comment="totem-devel is earlier than 0:2.28.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15311"/>
      <state state_ref="oval:org.mitre.oval:ste:34943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125915" version="1" comment="libpurple is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125909" version="1" comment="evolution-spamassassin is earlier than 0:2.32.3-30.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28742"/>
      <state state_ref="oval:org.mitre.oval:ste:34873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125908" version="1" comment="finch is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125896" version="1" comment="openchange-devel is earlier than 0:1.0-6.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28833"/>
      <state state_ref="oval:org.mitre.oval:ste:34835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125890" version="1" comment="totem-youtube is earlier than 0:2.28.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42276"/>
      <state state_ref="oval:org.mitre.oval:ste:34943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125889" version="1" comment="nautilus-sendto is earlier than 0:2.28.2-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42507"/>
      <state state_ref="oval:org.mitre.oval:ste:34556"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125865" version="1" comment="gnome-python2-libwnck is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42681"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125861" version="1" comment="libpurple-perl is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125850" version="1" comment="gnome-python2-evolution is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42397"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125845" version="1" comment="evolution-debuginfo is earlier than 0:2.32.3-30.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3809"/>
      <state state_ref="oval:org.mitre.oval:ste:34873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125835" version="1" comment="openchange is earlier than 0:1.0-6.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28856"/>
      <state state_ref="oval:org.mitre.oval:ste:34835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125816" version="1" comment="openchange-client is earlier than 0:1.0-6.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28931"/>
      <state state_ref="oval:org.mitre.oval:ste:34835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125797" version="1" comment="control-center is earlier than 0:2.28.1-39.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3775"/>
      <state state_ref="oval:org.mitre.oval:ste:34034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125794" version="1" comment="gnome-python2-desktop-debuginfo is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42591"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125789" version="1" comment="pidgin-perl is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125785" version="1" comment="gnome-python2-gnomedesktop is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42588"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125759" version="1" comment="evolution-perl is earlier than 0:2.32.3-30.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28952"/>
      <state state_ref="oval:org.mitre.oval:ste:34873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125757" version="1" comment="finch-devel is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125752" version="1" comment="gnome-python2-evince is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42355"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125743" version="1" comment="gnome-python2-desktop is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42144"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125720" version="1" comment="gtkhtml3-devel is earlier than 0:3.32.2-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42269"/>
      <state state_ref="oval:org.mitre.oval:ste:34753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125712" version="1" comment="gnome-python2-applet is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42577"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125710" version="1" comment="cheese-debuginfo is earlier than 0:2.28.1-8.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42467"/>
      <state state_ref="oval:org.mitre.oval:ste:34957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125706" version="1" comment="planner-debuginfo is earlier than 0:0.14.4-10.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42753"/>
      <state state_ref="oval:org.mitre.oval:ste:34374"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125694" version="1" comment="cheese is earlier than 0:2.28.1-8.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42410"/>
      <state state_ref="oval:org.mitre.oval:ste:34957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125686" version="1" comment="evolution-help is earlier than 0:2.32.3-30.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14325"/>
      <state state_ref="oval:org.mitre.oval:ste:34873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125677" version="1" comment="evolution-data-server is earlier than 0:2.32.3-18.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14939"/>
      <state state_ref="oval:org.mitre.oval:ste:34798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125638" version="1" comment="totem is earlier than 0:2.28.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15296"/>
      <state state_ref="oval:org.mitre.oval:ste:34943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125625" version="1" comment="gnome-python2-bugbuddy is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42017"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125619" version="1" comment="ekiga-debuginfo is earlier than 0:3.2.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4313"/>
      <state state_ref="oval:org.mitre.oval:ste:35019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125611" version="1" comment="totem-upnp is earlier than 0:2.28.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42626"/>
      <state state_ref="oval:org.mitre.oval:ste:34943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125610" version="1" comment="evolution-data-server-devel is earlier than 0:2.32.3-18.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14847"/>
      <state state_ref="oval:org.mitre.oval:ste:34798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125599" version="1" comment="gnome-python2-metacity is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42713"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125584" version="1" comment="planner-devel is earlier than 0:0.14.4-10.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42204"/>
      <state state_ref="oval:org.mitre.oval:ste:34374"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125572" version="1" comment="nautilus-sendto-devel is earlier than 0:2.28.2-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41789"/>
      <state state_ref="oval:org.mitre.oval:ste:34556"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125554" version="1" comment="gnome-python2-gtksourceview is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42240"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125553" version="1" comment="evolution-pst is earlier than 0:2.32.3-30.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29182"/>
      <state state_ref="oval:org.mitre.oval:ste:34873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125539" version="1" comment="ekiga is earlier than 0:3.2.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4126"/>
      <state state_ref="oval:org.mitre.oval:ste:35019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125509" version="1" comment="libpurple-tcl is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125445" version="1" comment="libgdata-debuginfo is earlier than 0:0.6.4-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42752"/>
      <state state_ref="oval:org.mitre.oval:ste:34863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125400" version="1" comment="openchange-debuginfo is earlier than 0:1.0-6.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42246"/>
      <state state_ref="oval:org.mitre.oval:ste:34835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125393" version="1" comment="openchange-devel-docs is earlier than 0:1.0-6.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28838"/>
      <state state_ref="oval:org.mitre.oval:ste:34835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125375" version="1" comment="nautilus-sendto-debuginfo is earlier than 0:2.28.2-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42533"/>
      <state state_ref="oval:org.mitre.oval:ste:34556"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125346" version="1" comment="gnome-panel-libs is earlier than 0:2.30.2-15.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42714"/>
      <state state_ref="oval:org.mitre.oval:ste:34557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125332" version="1" comment="libpurple-devel is earlier than 0:2.7.9-11.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:34350"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125298" version="1" comment="gnome-python2-gnomekeyring is earlier than 0:2.28.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42712"/>
      <state state_ref="oval:org.mitre.oval:ste:34537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125282" version="1" comment="gnome-panel is earlier than 0:2.30.2-15.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4548"/>
      <state state_ref="oval:org.mitre.oval:ste:34557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125273" version="1" comment="libgdata is earlier than 0:0.6.4-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42578"/>
      <state state_ref="oval:org.mitre.oval:ste:34863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125238" version="1" comment="totem-debuginfo is earlier than 0:2.28.6-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42641"/>
      <state state_ref="oval:org.mitre.oval:ste:34943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125188" version="1" comment="evolution-mapi-debuginfo is earlier than 0:0.32.2-12.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42638"/>
      <state state_ref="oval:org.mitre.oval:ste:34508"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137596" version="1" comment="file-debuginfo is earlier than 0:5.04-21.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44122"/>
      <state state_ref="oval:org.mitre.oval:ste:37635"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125284" version="1" comment="file-devel is earlier than 0:5.04-21.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41688"/>
      <state state_ref="oval:org.mitre.oval:ste:33902"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125271" version="1" comment="file-static is earlier than 0:5.04-21.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42400"/>
      <state state_ref="oval:org.mitre.oval:ste:33902"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125016" version="1" comment="file-libs is earlier than 0:5.04-21.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42201"/>
      <state state_ref="oval:org.mitre.oval:ste:33902"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125014" version="1" comment="python-magic is earlier than 0:5.04-21.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42079"/>
      <state state_ref="oval:org.mitre.oval:ste:33902"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125002" version="1" comment="file is earlier than 0:5.04-21.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14618"/>
      <state state_ref="oval:org.mitre.oval:ste:33902"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126169" version="2" comment="openssh-clients is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14409"/>
      <state state_ref="oval:org.mitre.oval:ste:34589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126151" version="2" comment="pam_ssh_agent_auth is earlier than 0:0.9.3-94.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29349"/>
      <state state_ref="oval:org.mitre.oval:ste:34992"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126150" version="2" comment="openssh-askpass is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14577"/>
      <state state_ref="oval:org.mitre.oval:ste:34589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126082" version="2" comment="openssh is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14581"/>
      <state state_ref="oval:org.mitre.oval:ste:34589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125742" version="3" comment="openssh-debuginfo is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42383"/>
      <state state_ref="oval:org.mitre.oval:ste:34589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125504" version="2" comment="openssh-ldap is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29531"/>
      <state state_ref="oval:org.mitre.oval:ste:34589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125500" version="2" comment="openssh-server is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14544"/>
      <state state_ref="oval:org.mitre.oval:ste:34589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138390" version="1" comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42704"/>
      <state state_ref="oval:org.mitre.oval:ste:37714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138328" version="1" comment="kernel-debuginfo-common-i686 is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42774"/>
      <state state_ref="oval:org.mitre.oval:ste:37714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138123" version="1" comment="kernel-debuginfo is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42117"/>
      <state state_ref="oval:org.mitre.oval:ste:37714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138095" version="1" comment="perf-debuginfo is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42724"/>
      <state state_ref="oval:org.mitre.oval:ste:37714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138041" version="1" comment="python-perf-debuginfo is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43043"/>
      <state state_ref="oval:org.mitre.oval:ste:37714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137928" version="1" comment="kernel-debug-debuginfo is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42590"/>
      <state state_ref="oval:org.mitre.oval:ste:37714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125303" version="1" comment="kernel-abi-whitelists is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29639"/>
      <state state_ref="oval:org.mitre.oval:ste:33776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125201" version="1" comment="kernel-firmware is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:33776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125193" version="1" comment="kernel-debug is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:33776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125192" version="1" comment="kernel-headers is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:33776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125125" version="1" comment="kernel-devel is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:33776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125087" version="1" comment="kernel-doc is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:33776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125082" version="1" comment="kernel is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:33776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124896" version="1" comment="perf is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:33776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124490" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:33776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124312" version="1" comment="python-perf is earlier than 0:2.6.32-504.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:33776"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126182" version="1" comment="openssh-server is earlier than 0:5.3p1-84.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14544"/>
      <state state_ref="oval:org.mitre.oval:ste:34642"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126146" version="1" comment="openssh-askpass is earlier than 0:5.3p1-84.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14577"/>
      <state state_ref="oval:org.mitre.oval:ste:34642"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126124" version="1" comment="pam_ssh_agent_auth is earlier than 0:0.9.3-84.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29349"/>
      <state state_ref="oval:org.mitre.oval:ste:34983"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126032" version="1" comment="openssh-clients is earlier than 0:5.3p1-84.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14409"/>
      <state state_ref="oval:org.mitre.oval:ste:34642"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125987" version="2" comment="openssh-debuginfo is earlier than 0:5.3p1-84.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42383"/>
      <state state_ref="oval:org.mitre.oval:ste:34642"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125479" version="1" comment="openssh is earlier than 0:5.3p1-84.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14581"/>
      <state state_ref="oval:org.mitre.oval:ste:34642"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125331" version="1" comment="openssh-ldap is earlier than 0:5.3p1-84.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29531"/>
      <state state_ref="oval:org.mitre.oval:ste:34642"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141228" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141206" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141202" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141151" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141147" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141137" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141080" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140941" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140933" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140874" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140660" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.3.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:39479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140292" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:39349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125368" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125319" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125276" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125249" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125088" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125078" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.85-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:34801"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126061" version="1" comment="subversion-debuginfo is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42619"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126055" version="1" comment="subversion-perl is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14470"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126051" version="1" comment="subversion-kde is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29565"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126034" version="1" comment="subversion is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15298"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126009" version="1" comment="subversion-devel is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14983"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126006" version="1" comment="subversion-perl is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14470"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125974" version="1" comment="subversion-devel is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14983"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125964" version="1" comment="subversion-debuginfo is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42619"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125958" version="1" comment="subversion-javahl is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15180"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125809" version="1" comment="subversion-ruby is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15192"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125681" version="1" comment="mod_dav_svn is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14514"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125525" version="1" comment="subversion-svn2cl is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29417"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125508" version="1" comment="subversion-javahl is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15180"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125411" version="1" comment="mod_dav_svn is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14514"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125069" version="1" comment="subversion-gnome is earlier than 0:1.6.11-10.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29010"/>
      <state state_ref="oval:org.mitre.oval:ste:34245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125062" version="1" comment="subversion-ruby is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15192"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125048" version="1" comment="subversion is earlier than 0:1.6.11-12.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15298"/>
      <state state_ref="oval:org.mitre.oval:ste:34919"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138122" version="1" comment="cups-debuginfo is earlier than 1:1.4.2-67.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:2902"/>
      <state state_ref="oval:org.mitre.oval:ste:38496"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125225" version="1" comment="cups-lpd is earlier than 1:1.4.2-67.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14688"/>
      <state state_ref="oval:org.mitre.oval:ste:34073"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125208" version="1" comment="cups-devel is earlier than 1:1.4.2-67.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:34073"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124980" version="1" comment="cups-libs is earlier than 1:1.4.2-67.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:34073"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124607" version="1" comment="cups-php is earlier than 1:1.4.2-67.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29023"/>
      <state state_ref="oval:org.mitre.oval:ste:34073"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124470" version="1" comment="cups is earlier than 1:1.4.2-67.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:34073"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126178" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:34896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126166" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:34896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126128" version="1" comment="xorg-x11-server-source is earlier than 0:1.13.0-23.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28734"/>
      <state state_ref="oval:org.mitre.oval:ste:34896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126113" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:34896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126111" version="1" comment="xorg-x11-server-source is earlier than 0:1.13.0-23.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28734"/>
      <state state_ref="oval:org.mitre.oval:ste:34198"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126078" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:34896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125954" version="1" comment="xorg-x11-server-debuginfo is earlier than 0:1.13.0-23.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42697"/>
      <state state_ref="oval:org.mitre.oval:ste:34198"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125895" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:34198"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125869" version="1" comment="xorg-x11-server-common is earlier than 0:1.13.0-23.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28695"/>
      <state state_ref="oval:org.mitre.oval:ste:34896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125863" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.13.0-23.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:34198"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125853" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.13.0-23.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:34198"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125802" version="1" comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28915"/>
      <state state_ref="oval:org.mitre.oval:ste:34198"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125687" version="1" comment="xorg-x11-server-devel is earlier than 0:1.13.0-23.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28915"/>
      <state state_ref="oval:org.mitre.oval:ste:34896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125672" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.13.0-23.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:34896"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125475" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.13.0-23.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:34198"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125187" version="1" comment="xorg-x11-server-common is earlier than 0:1.13.0-23.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28695"/>
      <state state_ref="oval:org.mitre.oval:ste:34198"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125180" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.13.0-23.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:34198"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126307" version="1" comment="cups-php is earlier than 0:1.4.2-44.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29023"/>
      <state state_ref="oval:org.mitre.oval:ste:35049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126210" version="1" comment="cups is earlier than 0:1.4.2-44.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:35049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126195" version="1" comment="cups-devel is earlier than 0:1.4.2-44.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:35049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125495" version="1" comment="cups-lpd is earlier than 0:1.4.2-44.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14688"/>
      <state state_ref="oval:org.mitre.oval:ste:35049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125433" version="1" comment="cups-debuginfo is earlier than 0:1.4.2-44.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:2902"/>
      <state state_ref="oval:org.mitre.oval:ste:35049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125345" version="1" comment="cups-libs is earlier than 0:1.4.2-44.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:35049"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126143" version="1" comment="php-recode is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126132" version="1" comment="php-pgsql is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126094" version="1" comment="php-snmp is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126093" version="1" comment="php-intl is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126090" version="1" comment="php-debuginfo is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42299"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126088" version="1" comment="php-ldap is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126066" version="1" comment="php-mbstring is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126017" version="1" comment="php-devel is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125986" version="1" comment="php-zts is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29304"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125980" version="1" comment="php-xml is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125971" version="1" comment="php-gd is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125963" version="1" comment="php-imap is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125956" version="1" comment="php-enchant is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125936" version="1" comment="php-dba is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125913" version="1" comment="php-embedded is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125899" version="1" comment="php-mysql is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125841" version="1" comment="php-odbc is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125791" version="1" comment="php-cli is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125732" version="1" comment="php-bcmath is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125729" version="1" comment="php-fpm is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29228"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125630" version="1" comment="php-pdo is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125595" version="1" comment="php-tidy is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28881"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125576" version="1" comment="php-soap is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125573" version="1" comment="php is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125541" version="1" comment="php-pspell is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125408" version="1" comment="php-common is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125153" version="1" comment="php-xmlrpc is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125148" version="1" comment="php-process is earlier than 0:5.3.3-26.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:34960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126346" version="1" comment="uuidd is earlier than 0:2.17.2-12.4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29226"/>
      <state state_ref="oval:org.mitre.oval:ste:34493"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126292" version="1" comment="libblkid is earlier than 0:2.17.2-12.4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29189"/>
      <state state_ref="oval:org.mitre.oval:ste:34493"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126287" version="1" comment="libblkid-devel is earlier than 0:2.17.2-12.4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28768"/>
      <state state_ref="oval:org.mitre.oval:ste:34493"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126185" version="1" comment="util-linux-ng is earlier than 0:2.17.2-12.4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28554"/>
      <state state_ref="oval:org.mitre.oval:ste:34493"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126138" version="1" comment="libuuid-devel is earlier than 0:2.17.2-12.4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29300"/>
      <state state_ref="oval:org.mitre.oval:ste:34493"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125947" version="1" comment="util-linux-ng-debuginfo is earlier than 0:2.17.2-12.4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42743"/>
      <state state_ref="oval:org.mitre.oval:ste:34493"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125514" version="1" comment="libuuid is earlier than 0:2.17.2-12.4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29275"/>
      <state state_ref="oval:org.mitre.oval:ste:34493"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126171" version="1" comment="dovecot-pgsql is earlier than 0:2.0.9-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30241"/>
      <state state_ref="oval:org.mitre.oval:ste:34774"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126145" version="1" comment="dovecot-devel is earlier than 0:2.0.9-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4212"/>
      <state state_ref="oval:org.mitre.oval:ste:34774"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126011" version="1" comment="dovecot is earlier than 0:2.0.9-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3572"/>
      <state state_ref="oval:org.mitre.oval:ste:34774"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125970" version="1" comment="dovecot-debuginfo is earlier than 0:2.0.9-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4278"/>
      <state state_ref="oval:org.mitre.oval:ste:34774"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125926" version="1" comment="dovecot-mysql is earlier than 0:2.0.9-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29698"/>
      <state state_ref="oval:org.mitre.oval:ste:34774"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125880" version="1" comment="dovecot-pigeonhole is earlier than 0:2.0.9-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30040"/>
      <state state_ref="oval:org.mitre.oval:ste:34774"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125955" version="1" comment="virt-v2v is earlier than 0:0.8.3-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42376"/>
      <state state_ref="oval:org.mitre.oval:ste:34514"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138301" version="1" comment="java-1.8.0-openjdk-debuginfo is earlier than 0:1.8.0.25-1.b17.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43900"/>
      <state state_ref="oval:org.mitre.oval:ste:38462"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125366" version="1" comment="java-1.8.0-openjdk-src is earlier than 0:1.8.0.25-1.b17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42385"/>
      <state state_ref="oval:org.mitre.oval:ste:34646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125351" version="1" comment="java-1.8.0-openjdk is earlier than 0:1.8.0.25-1.b17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41937"/>
      <state state_ref="oval:org.mitre.oval:ste:34646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125330" version="1" comment="java-1.8.0-openjdk-demo is earlier than 0:1.8.0.25-1.b17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42346"/>
      <state state_ref="oval:org.mitre.oval:ste:34646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125269" version="1" comment="java-1.8.0-openjdk-headless is earlier than 0:1.8.0.25-1.b17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42427"/>
      <state state_ref="oval:org.mitre.oval:ste:34646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125265" version="1" comment="java-1.8.0-openjdk-devel is earlier than 0:1.8.0.25-1.b17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42172"/>
      <state state_ref="oval:org.mitre.oval:ste:34646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124967" version="1" comment="java-1.8.0-openjdk-javadoc is earlier than 0:1.8.0.25-1.b17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42445"/>
      <state state_ref="oval:org.mitre.oval:ste:34646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126071" version="1" comment="wireshark is earlier than 0:1.8.10-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:34654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125702" version="1" comment="wireshark-devel is earlier than 0:1.8.10-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30148"/>
      <state state_ref="oval:org.mitre.oval:ste:34654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125684" version="1" comment="wireshark-debuginfo is earlier than 0:1.8.10-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42668"/>
      <state state_ref="oval:org.mitre.oval:ste:34654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125544" version="1" comment="wireshark-gnome is earlier than 0:1.8.10-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:34654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126320" version="1" comment="qemu-kvm-tools is earlier than 0:0.12.1.2-2.209.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:34315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126276" version="1" comment="qemu-img is earlier than 0:0.12.1.2-2.209.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29180"/>
      <state state_ref="oval:org.mitre.oval:ste:34315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126257" version="1" comment="qemu-kvm is earlier than 0:0.12.1.2-2.209.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29139"/>
      <state state_ref="oval:org.mitre.oval:ste:34315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125938" version="1" comment="qemu-kvm-debuginfo is earlier than 0:0.12.1.2-2.209.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42615"/>
      <state state_ref="oval:org.mitre.oval:ste:34315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126274" version="1" comment="nfs-utils is earlier than 0:1.2.3-15.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14333"/>
      <state state_ref="oval:org.mitre.oval:ste:34839"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126271" version="1" comment="nfs-utils-debuginfo is earlier than 0:1.2.3-15.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42139"/>
      <state state_ref="oval:org.mitre.oval:ste:34839"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126140" version="1" comment="php-pear is earlier than 0:1.9.4-4.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14130"/>
      <state state_ref="oval:org.mitre.oval:ste:34639"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138217" version="1" comment="trousers-debuginfo is earlier than 0:0.3.13-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44017"/>
      <state state_ref="oval:org.mitre.oval:ste:38528"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125305" version="1" comment="trousers-devel is earlier than 0:0.3.13-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41529"/>
      <state state_ref="oval:org.mitre.oval:ste:34730"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125151" version="1" comment="trousers-static is earlier than 0:0.3.13-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42301"/>
      <state state_ref="oval:org.mitre.oval:ste:34730"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124549" version="1" comment="trousers is earlier than 0:0.3.13-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39909"/>
      <state state_ref="oval:org.mitre.oval:ste:34730"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138261" version="1" comment="krb5-debuginfo is earlier than 0:1.10.3-33.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44140"/>
      <state state_ref="oval:org.mitre.oval:ste:38430"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125280" version="1" comment="krb5-workstation is earlier than 0:1.10.3-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:34477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124936" version="1" comment="krb5-server is earlier than 0:1.10.3-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:34477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124907" version="1" comment="krb5-pkinit-openssl is earlier than 0:1.10.3-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29392"/>
      <state state_ref="oval:org.mitre.oval:ste:34477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124879" version="1" comment="krb5-devel is earlier than 0:1.10.3-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:34477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124840" version="1" comment="krb5-server-ldap is earlier than 0:1.10.3-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29451"/>
      <state state_ref="oval:org.mitre.oval:ste:34477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124306" version="1" comment="krb5-libs is earlier than 0:1.10.3-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:34477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126099" version="1" comment="augeas is earlier than 0:1.0.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30397"/>
      <state state_ref="oval:org.mitre.oval:ste:34953"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126098" version="1" comment="augeas-devel is earlier than 0:1.0.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30286"/>
      <state state_ref="oval:org.mitre.oval:ste:34953"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125940" version="1" comment="augeas-debuginfo is earlier than 0:1.0.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42199"/>
      <state state_ref="oval:org.mitre.oval:ste:34953"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125418" version="1" comment="augeas-libs is earlier than 0:1.0.0-5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30408"/>
      <state state_ref="oval:org.mitre.oval:ste:34953"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141226" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28501"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141212" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141211" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28813"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141191" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141169" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141161" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141116" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140953" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28813"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140948" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140918" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140729" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.2.el7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:39094"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140719" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28501"/>
      <state state_ref="oval:org.mitre.oval:ste:39173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125348" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28813"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125339" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125290" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125274" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125233" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124966" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.72-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28501"/>
      <state state_ref="oval:org.mitre.oval:ste:34718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126312" version="1" comment="ruby-tcltk is earlier than 0:1.8.7.352-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:34881"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126299" version="1" comment="ruby is earlier than 0:1.8.7.352-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:34881"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126290" version="1" comment="ruby-irb is earlier than 0:1.8.7.352-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14777"/>
      <state state_ref="oval:org.mitre.oval:ste:34881"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126136" version="1" comment="ruby-debuginfo is earlier than 0:1.8.7.352-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42519"/>
      <state state_ref="oval:org.mitre.oval:ste:34881"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126127" version="1" comment="ruby-devel is earlier than 0:1.8.7.352-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:34881"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126112" version="1" comment="ruby-rdoc is earlier than 0:1.8.7.352-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14244"/>
      <state state_ref="oval:org.mitre.oval:ste:34881"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125937" version="1" comment="ruby-docs is earlier than 0:1.8.7.352-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:34881"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125924" version="1" comment="ruby-libs is earlier than 0:1.8.7.352-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:34881"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125473" version="1" comment="ruby-ri is earlier than 0:1.8.7.352-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14461"/>
      <state state_ref="oval:org.mitre.oval:ste:34881"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125358" version="1" comment="ruby-static is earlier than 0:1.8.7.352-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28990"/>
      <state state_ref="oval:org.mitre.oval:ste:34881"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125381" version="1" comment="firefox is earlier than 0:31.2.0-3.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34688"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125356" version="1" comment="firefox is earlier than 0:31.2.0-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125354" version="1" comment="xulrunner is earlier than 0:31.2.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:34644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125349" version="1" comment="xulrunner is earlier than 0:31.2.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:34819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125313" version="1" comment="xulrunner-devel is earlier than 0:31.2.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:34644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125112" version="1" comment="firefox is earlier than 0:31.2.0-3.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125107" version="1" comment="xulrunner-devel is earlier than 0:31.2.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:34819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125077" version="1" comment="firefox is earlier than 0:31.2.0-3.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34634"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124713" version="1" comment="firefox is earlier than 0:31.2.0-3.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34522"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125989" version="1" comment="wireshark is earlier than 0:1.10.3-12.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:34595"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125961" version="1" comment="wireshark-devel is earlier than 0:1.10.3-12.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30148"/>
      <state state_ref="oval:org.mitre.oval:ste:34595"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125950" version="1" comment="wireshark-gnome is earlier than 0:1.8.10-8.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:34463"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125925" version="1" comment="wireshark-debuginfo is earlier than 0:1.8.10-8.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42668"/>
      <state state_ref="oval:org.mitre.oval:ste:34463"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125819" version="1" comment="wireshark-debuginfo is earlier than 0:1.10.3-12.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42668"/>
      <state state_ref="oval:org.mitre.oval:ste:34595"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125647" version="1" comment="wireshark-devel is earlier than 0:1.8.10-8.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30148"/>
      <state state_ref="oval:org.mitre.oval:ste:34463"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125214" version="1" comment="wireshark is earlier than 0:1.8.10-8.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:34463"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125127" version="1" comment="wireshark-gnome is earlier than 0:1.10.3-12.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:34595"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125405" version="1" comment="openssl-static is earlier than 1:1.0.1e-34.el7_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:34727"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125398" version="1" comment="openssl-perl is earlier than 0:1.0.1e-30.el6_6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:34086"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125085" version="1" comment="openssl-perl is earlier than 1:1.0.1e-34.el7_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:34727"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124930" version="1" comment="openssl is earlier than 1:1.0.1e-34.el7_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:34727"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124925" version="1" comment="openssl is earlier than 0:1.0.1e-30.el6_6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:34086"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124881" version="1" comment="openssl-devel is earlier than 0:1.0.1e-30.el6_6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:34086"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124864" version="1" comment="openssl-libs is earlier than 1:1.0.1e-34.el7_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39297"/>
      <state state_ref="oval:org.mitre.oval:ste:34727"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124834" version="1" comment="openssl-devel is earlier than 1:1.0.1e-34.el7_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:34727"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124481" version="1" comment="openssl-static is earlier than 0:1.0.1e-30.el6_6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:34086"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123908" version="1" comment="axis is earlier than 0:1.2.1-2jpp.8.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3069"/>
      <state state_ref="oval:org.mitre.oval:ste:34370"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123903" version="1" comment="axis-javadoc is earlier than 0:1.2.1-7.5.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:2320"/>
      <state state_ref="oval:org.mitre.oval:ste:33934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123895" version="1" comment="axis-javadoc is earlier than 0:1.2.1-2jpp.8.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:2320"/>
      <state state_ref="oval:org.mitre.oval:ste:34370"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123761" version="1" comment="axis is earlier than 0:1.2.1-7.5.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3069"/>
      <state state_ref="oval:org.mitre.oval:ste:33934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123658" version="1" comment="axis-manual is earlier than 0:1.2.1-7.5.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3255"/>
      <state state_ref="oval:org.mitre.oval:ste:33934"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123598" version="1" comment="axis-manual is earlier than 0:1.2.1-2jpp.8.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3255"/>
      <state state_ref="oval:org.mitre.oval:ste:34370"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125906" version="1" comment="rsyslog5-pgsql is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42664"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125903" version="1" comment="rsyslog5-debuginfo is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42408"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125854" version="1" comment="rsyslog-debuginfo is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42620"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125806" version="1" comment="rsyslog5-gnutls is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42650"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125803" version="1" comment="rsyslog5-gssapi is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42111"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125788" version="1" comment="rsyslog5 is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42572"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125716" version="1" comment="rsyslog-gssapi is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29969"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125650" version="1" comment="rsyslog-relp is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29740"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125639" version="1" comment="rsyslog5-snmp is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42593"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125530" version="1" comment="rsyslog-snmp is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29239"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125524" version="1" comment="rsyslog is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29962"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125517" version="1" comment="rsyslog-mysql is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29867"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125503" version="1" comment="rsyslog-gnutls is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30163"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125341" version="1" comment="rsyslog-pgsql is earlier than 0:5.8.10-9.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29691"/>
      <state state_ref="oval:org.mitre.oval:ste:34980"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125338" version="1" comment="rsyslog5-mysql is earlier than 0:5.8.12-5.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42350"/>
      <state state_ref="oval:org.mitre.oval:ste:34862"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138319" version="1" comment="openssh-debuginfo is earlier than 0:5.3p1-104.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42383"/>
      <state state_ref="oval:org.mitre.oval:ste:38551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125378" version="1" comment="openssh-askpass is earlier than 0:5.3p1-104.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14577"/>
      <state state_ref="oval:org.mitre.oval:ste:34744"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125340" version="1" comment="pam_ssh_agent_auth is earlier than 0:0.9.3-104.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29349"/>
      <state state_ref="oval:org.mitre.oval:ste:34658"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125098" version="1" comment="openssh is earlier than 0:5.3p1-104.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14581"/>
      <state state_ref="oval:org.mitre.oval:ste:34744"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125037" version="1" comment="openssh-clients is earlier than 0:5.3p1-104.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14409"/>
      <state state_ref="oval:org.mitre.oval:ste:34744"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124984" version="1" comment="openssh-ldap is earlier than 0:5.3p1-104.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29531"/>
      <state state_ref="oval:org.mitre.oval:ste:34744"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124560" version="1" comment="openssh-server is earlier than 0:5.3p1-104.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14544"/>
      <state state_ref="oval:org.mitre.oval:ste:34744"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126296" version="1" comment="nscd is earlier than 0:2.12-1.47.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:34419"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126200" version="1" comment="glibc-headers is earlier than 0:2.12-1.47.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:34419"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126122" version="1" comment="glibc-utils is earlier than 0:2.12-1.47.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:34419"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126022" version="1" comment="glibc is earlier than 0:2.12-1.47.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:34419"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125984" version="1" comment="glibc-static is earlier than 0:2.12-1.47.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30224"/>
      <state state_ref="oval:org.mitre.oval:ste:34419"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125976" version="1" comment="glibc-debuginfo is earlier than 0:2.12-1.47.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4398"/>
      <state state_ref="oval:org.mitre.oval:ste:34419"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125973" version="1" comment="glibc-common is earlier than 0:2.12-1.47.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:34419"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125901" version="1" comment="glibc-debuginfo-common is earlier than 0:2.12-1.47.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42178"/>
      <state state_ref="oval:org.mitre.oval:ste:34419"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125334" version="1" comment="glibc-devel is earlier than 0:2.12-1.47.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:34419"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123872" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123813" version="1" comment="kernel is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123779" version="1" comment="kernel-firmware is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123755" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123750" version="1" comment="kernel-devel is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123742" version="1" comment="kernel-headers is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123669" version="1" comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29639"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123660" version="1" comment="kernel-kdump is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123394" version="1" comment="kernel-debug is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123353" version="1" comment="perf is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123144" version="1" comment="kernel-doc is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122937" version="1" comment="python-perf is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122932" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-431.29.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:34067"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138264" version="1" comment="rsyslog7-debuginfo is earlier than 0:7.4.10-3.el6_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44062"/>
      <state state_ref="oval:org.mitre.oval:ste:38503"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125385" version="1" comment="rsyslog7 is earlier than 0:7.4.10-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41654"/>
      <state state_ref="oval:org.mitre.oval:ste:34763"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125318" version="1" comment="rsyslog7-elasticsearch is earlier than 0:7.4.10-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42324"/>
      <state state_ref="oval:org.mitre.oval:ste:34763"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125297" version="1" comment="rsyslog7-mysql is earlier than 0:7.4.10-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42553"/>
      <state state_ref="oval:org.mitre.oval:ste:34763"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125287" version="1" comment="rsyslog7-relp is earlier than 0:7.4.10-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42521"/>
      <state state_ref="oval:org.mitre.oval:ste:34763"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125258" version="1" comment="rsyslog7-pgsql is earlier than 0:7.4.10-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42508"/>
      <state state_ref="oval:org.mitre.oval:ste:34763"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125230" version="1" comment="rsyslog7-gssapi is earlier than 0:7.4.10-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42325"/>
      <state state_ref="oval:org.mitre.oval:ste:34763"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124940" version="1" comment="rsyslog7-gnutls is earlier than 0:7.4.10-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41587"/>
      <state state_ref="oval:org.mitre.oval:ste:34763"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124421" version="1" comment="rsyslog7-snmp is earlier than 0:7.4.10-3.el6_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41700"/>
      <state state_ref="oval:org.mitre.oval:ste:34763"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138395" version="1" comment="libXi-debuginfo is earlier than 0:1.7.2-2.2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44019"/>
      <state state_ref="oval:org.mitre.oval:ste:38342"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138369" version="1" comment="libXp-debuginfo is earlier than 0:1.0.2-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43250"/>
      <state state_ref="oval:org.mitre.oval:ste:38072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138286" version="1" comment="libXxf86dga-debuginfo is earlier than 0:1.1.4-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43995"/>
      <state state_ref="oval:org.mitre.oval:ste:38537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138238" version="1" comment="libXrender-debuginfo is earlier than 0:0.9.8-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43812"/>
      <state state_ref="oval:org.mitre.oval:ste:38276"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138236" version="1" comment="libXinerama-debuginfo is earlier than 0:1.1.3-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44118"/>
      <state state_ref="oval:org.mitre.oval:ste:37577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138234" version="1" comment="libXt-debuginfo is earlier than 0:1.1.4-6.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44105"/>
      <state state_ref="oval:org.mitre.oval:ste:38575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138225" version="1" comment="libXvMC-debuginfo is earlier than 0:1.0.8-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43520"/>
      <state state_ref="oval:org.mitre.oval:ste:38153"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138151" version="1" comment="libXfixes-debuginfo is earlier than 0:5.0.1-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44087"/>
      <state state_ref="oval:org.mitre.oval:ste:38507"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138102" version="1" comment="libXxf86vm-debuginfo is earlier than 0:1.1.3-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44124"/>
      <state state_ref="oval:org.mitre.oval:ste:37577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138079" version="1" comment="libXrandr-debuginfo is earlier than 0:1.4.1-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44003"/>
      <state state_ref="oval:org.mitre.oval:ste:38385"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138066" version="1" comment="libXcursor-debuginfo is earlier than 0:1.1.14-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43608"/>
      <state state_ref="oval:org.mitre.oval:ste:38140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138062" version="1" comment="libX11-debuginfo is earlier than 0:1.6.0-2.2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43982"/>
      <state state_ref="oval:org.mitre.oval:ste:38367"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137961" version="1" comment="libXv-debuginfo is earlier than 0:1.0.9-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43979"/>
      <state state_ref="oval:org.mitre.oval:ste:38010"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137944" version="1" comment="libxcb-debuginfo is earlier than 0:1.9.1-2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43282"/>
      <state state_ref="oval:org.mitre.oval:ste:37819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137884" version="1" comment="libXtst-debuginfo is earlier than 0:1.2.2-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44079"/>
      <state state_ref="oval:org.mitre.oval:ste:38463"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137832" version="1" comment="libXres-debuginfo is earlier than 0:1.0.7-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44075"/>
      <state state_ref="oval:org.mitre.oval:ste:38578"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137713" version="1" comment="libdmx-debuginfo is earlier than 0:1.1.3-3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:44126"/>
      <state state_ref="oval:org.mitre.oval:ste:38374"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137467" version="1" comment="libXext-debuginfo is earlier than 0:1.3.2-2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43714"/>
      <state state_ref="oval:org.mitre.oval:ste:38481"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125396" version="1" comment="libXrandr-devel is earlier than 0:1.4.1-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42374"/>
      <state state_ref="oval:org.mitre.oval:ste:34316"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125392" version="1" comment="libXxf86dga is earlier than 0:1.1.4-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42051"/>
      <state state_ref="oval:org.mitre.oval:ste:34348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125389" version="1" comment="libXtst-devel is earlier than 0:1.2.2-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42347"/>
      <state state_ref="oval:org.mitre.oval:ste:33823"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125388" version="1" comment="libX11-devel is earlier than 0:1.6.0-2.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14309"/>
      <state state_ref="oval:org.mitre.oval:ste:34372"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125386" version="1" comment="libxcb-python is earlier than 0:1.9.1-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42293"/>
      <state state_ref="oval:org.mitre.oval:ste:34679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125376" version="1" comment="libxcb-devel is earlier than 0:1.9.1-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42488"/>
      <state state_ref="oval:org.mitre.oval:ste:34679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125369" version="1" comment="libX11 is earlier than 0:1.6.0-2.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14749"/>
      <state state_ref="oval:org.mitre.oval:ste:34372"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125365" version="1" comment="xorg-x11-xtrans-devel is earlier than 0:1.3.4-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41932"/>
      <state state_ref="oval:org.mitre.oval:ste:34359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125363" version="1" comment="libXxf86dga-devel is earlier than 0:1.1.4-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42226"/>
      <state state_ref="oval:org.mitre.oval:ste:34348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125362" version="1" comment="libxcb is earlier than 0:1.9.1-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42094"/>
      <state state_ref="oval:org.mitre.oval:ste:34679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125357" version="1" comment="libXvMC-devel is earlier than 0:1.0.8-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41689"/>
      <state state_ref="oval:org.mitre.oval:ste:34772"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125329" version="1" comment="xcb-proto is earlier than 0:1.8-3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42195"/>
      <state state_ref="oval:org.mitre.oval:ste:34355"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125309" version="1" comment="libdmx is earlier than 0:1.1.3-3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42272"/>
      <state state_ref="oval:org.mitre.oval:ste:34681"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125302" version="1" comment="libXxf86vm-devel is earlier than 0:1.1.3-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41875"/>
      <state state_ref="oval:org.mitre.oval:ste:34631"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125296" version="1" comment="xkeyboard-config-devel is earlier than 0:2.11-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42443"/>
      <state state_ref="oval:org.mitre.oval:ste:34794"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125283" version="1" comment="libXi-devel is earlier than 0:1.7.2-2.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42315"/>
      <state state_ref="oval:org.mitre.oval:ste:34783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125255" version="1" comment="libXrender-devel is earlier than 0:0.9.8-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42263"/>
      <state state_ref="oval:org.mitre.oval:ste:34684"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125251" version="1" comment="libXrender is earlier than 0:0.9.8-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42300"/>
      <state state_ref="oval:org.mitre.oval:ste:34684"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125247" version="1" comment="libXt is earlier than 0:1.1.4-6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42413"/>
      <state state_ref="oval:org.mitre.oval:ste:34725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125240" version="1" comment="libdmx-devel is earlier than 0:1.1.3-3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42398"/>
      <state state_ref="oval:org.mitre.oval:ste:34681"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125219" version="1" comment="libXfixes-devel is earlier than 0:5.0.1-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42227"/>
      <state state_ref="oval:org.mitre.oval:ste:34204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125197" version="1" comment="libXres-devel is earlier than 0:1.0.7-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42209"/>
      <state state_ref="oval:org.mitre.oval:ste:34704"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125195" version="1" comment="libXinerama-devel is earlier than 0:1.1.3-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42433"/>
      <state state_ref="oval:org.mitre.oval:ste:34631"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125194" version="1" comment="libX11-common is earlier than 0:1.6.0-2.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42198"/>
      <state state_ref="oval:org.mitre.oval:ste:34372"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125186" version="1" comment="libXv-devel is earlier than 0:1.0.9-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42050"/>
      <state state_ref="oval:org.mitre.oval:ste:34278"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125175" version="1" comment="libXinerama is earlier than 0:1.1.3-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42133"/>
      <state state_ref="oval:org.mitre.oval:ste:34631"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125167" version="1" comment="libXp-devel is earlier than 0:1.0.2-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42469"/>
      <state state_ref="oval:org.mitre.oval:ste:34349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125155" version="1" comment="libXext-devel is earlier than 0:1.3.2-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41512"/>
      <state state_ref="oval:org.mitre.oval:ste:34532"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125143" version="1" comment="libXtst is earlier than 0:1.2.2-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42250"/>
      <state state_ref="oval:org.mitre.oval:ste:33823"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125114" version="1" comment="xkeyboard-config is earlier than 0:2.11-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:40296"/>
      <state state_ref="oval:org.mitre.oval:ste:34794"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125106" version="1" comment="libXfixes is earlier than 0:5.0.1-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42100"/>
      <state state_ref="oval:org.mitre.oval:ste:34204"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125097" version="1" comment="libXi is earlier than 0:1.7.2-2.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42232"/>
      <state state_ref="oval:org.mitre.oval:ste:34783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125070" version="1" comment="libXt-devel is earlier than 0:1.1.4-6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42362"/>
      <state state_ref="oval:org.mitre.oval:ste:34725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125057" version="1" comment="libXxf86vm is earlier than 0:1.1.3-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42407"/>
      <state state_ref="oval:org.mitre.oval:ste:34631"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124987" version="1" comment="libXcursor is earlier than 0:1.1.14-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42475"/>
      <state state_ref="oval:org.mitre.oval:ste:34661"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124975" version="1" comment="libxcb-doc is earlier than 0:1.9.1-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42106"/>
      <state state_ref="oval:org.mitre.oval:ste:34679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124962" version="1" comment="xorg-x11-proto-devel is earlier than 0:7.7-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42132"/>
      <state state_ref="oval:org.mitre.oval:ste:34824"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124902" version="1" comment="libXp is earlier than 0:1.0.2-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42306"/>
      <state state_ref="oval:org.mitre.oval:ste:34349"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124897" version="1" comment="libXext is earlier than 0:1.3.2-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42211"/>
      <state state_ref="oval:org.mitre.oval:ste:34532"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124895" version="1" comment="libXres is earlier than 0:1.0.7-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42261"/>
      <state state_ref="oval:org.mitre.oval:ste:34704"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124853" version="1" comment="libXcursor-devel is earlier than 0:1.1.14-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41910"/>
      <state state_ref="oval:org.mitre.oval:ste:34661"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124708" version="1" comment="libXv is earlier than 0:1.0.9-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41834"/>
      <state state_ref="oval:org.mitre.oval:ste:34278"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124530" version="1" comment="libXvMC is earlier than 0:1.0.8-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42406"/>
      <state state_ref="oval:org.mitre.oval:ste:34772"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124396" version="1" comment="libXrandr is earlier than 0:1.4.1-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42330"/>
      <state state_ref="oval:org.mitre.oval:ste:34316"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135359" version="1" comment="nss-debuginfo is earlier than 0:3.16.1-4.el5_11" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37507"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135339" version="1" comment="nss-util-debuginfo is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42869"/>
      <state state_ref="oval:org.mitre.oval:ste:37336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135333" version="1" comment="nss-softokn-debuginfo is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43053"/>
      <state state_ref="oval:org.mitre.oval:ste:37336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135328" version="1" comment="nss-softokn-debuginfo is earlier than 0:3.14.3-12.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43053"/>
      <state state_ref="oval:org.mitre.oval:ste:36556"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135234" version="1" comment="nss-debuginfo is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135090" version="1" comment="nss-util-debuginfo is earlier than 0:3.16.1-2.el6_5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42869"/>
      <state state_ref="oval:org.mitre.oval:ste:36573"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:134839" version="1" comment="nss-debuginfo is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37178"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124011" version="1" comment="nss-softokn is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29421"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123982" version="1" comment="nss-softokn-freebl is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29159"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123968" version="1" comment="nss-softokn-freebl-devel is earlier than 0:3.14.3-12.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29515"/>
      <state state_ref="oval:org.mitre.oval:ste:34365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123954" version="1" comment="nss-tools is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:33988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123944" version="1" comment="nss-tools is earlier than 0:3.16.1-4.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:34244"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123916" version="1" comment="nss-softokn-devel is earlier than 0:3.14.3-12.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29485"/>
      <state state_ref="oval:org.mitre.oval:ste:34365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123897" version="1" comment="nss is earlier than 0:3.16.1-4.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:34244"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123896" version="1" comment="nss-softokn-freebl-devel is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29515"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123883" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:33988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123878" version="1" comment="nss-devel is earlier than 0:3.16.1-4.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:34244"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123873" version="1" comment="nss-devel is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:34353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123871" version="1" comment="nss-softokn-freebl is earlier than 0:3.14.3-12.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29159"/>
      <state state_ref="oval:org.mitre.oval:ste:34365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123851" version="1" comment="nss-tools is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:34353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123832" version="1" comment="nss-devel is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:33988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123826" version="1" comment="nss is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:33988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123805" version="1" comment="nss-util is earlier than 0:3.16.1-2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:34415"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123793" version="1" comment="nss-util is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123771" version="1" comment="nss-sysinit is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:34353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123768" version="1" comment="nss-util-devel is earlier than 0:3.16.1-2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:34415"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123719" version="1" comment="nss-softokn-devel is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29485"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123673" version="1" comment="nss-softokn is earlier than 0:3.14.3-12.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29421"/>
      <state state_ref="oval:org.mitre.oval:ste:34365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123650" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:34353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123492" version="1" comment="nss is earlier than 0:3.16.2-7.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:34353"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123201" version="1" comment="nss-sysinit is earlier than 0:3.16.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:33988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123190" version="1" comment="nss-util-devel is earlier than 0:3.16.2-2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:34396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123032" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.1-4.el5_11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:34244"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122939" version="1" comment="squid is earlier than 7:3.1.10-22.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14403"/>
      <state state_ref="oval:org.mitre.oval:ste:33869"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122890" version="1" comment="squid is earlier than 7:2.6.STABLE21-7.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14403"/>
      <state state_ref="oval:org.mitre.oval:ste:33754"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126106" version="2" comment="glibc-devel is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:34035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126086" version="2" comment="glibc is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:34035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125878" version="2" comment="glibc-common is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:34035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125781" version="2" comment="glibc-static is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30224"/>
      <state state_ref="oval:org.mitre.oval:ste:34035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125748" version="2" comment="glibc-utils is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:34035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125691" version="2" comment="nscd is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:34035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125632" version="2" comment="glibc-headers is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:34035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125344" version="2" comment="glibc-debuginfo-common is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42178"/>
      <state state_ref="oval:org.mitre.oval:ste:34035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125137" version="2" comment="glibc-debuginfo is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="all" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4398"/>
      <state state_ref="oval:org.mitre.oval:ste:34035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123869" version="1" comment="flash-plugin is earlier than 0:11.2.202.406-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:34422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123356" version="1" comment="flash-plugin is earlier than 0:11.2.202.406-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:34134"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123036" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29139"/>
      <state state_ref="oval:org.mitre.oval:ste:33970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122814" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:33970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122690" version="1" comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29180"/>
      <state state_ref="oval:org.mitre.oval:ste:33970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122675" version="1" comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28988"/>
      <state state_ref="oval:org.mitre.oval:ste:33970"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126048" version="1" comment="pacemaker-libs is earlier than 0:1.1.10-14.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42428"/>
      <state state_ref="oval:org.mitre.oval:ste:34956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:126043" version="1" comment="pacemaker-cluster-libs is earlier than 0:1.1.10-14.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42762"/>
      <state state_ref="oval:org.mitre.oval:ste:34956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125991" version="1" comment="pacemaker-cli is earlier than 0:1.1.10-14.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42353"/>
      <state state_ref="oval:org.mitre.oval:ste:34956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125912" version="1" comment="pacemaker-cts is earlier than 0:1.1.10-14.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42783"/>
      <state state_ref="oval:org.mitre.oval:ste:34956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125891" version="1" comment="pacemaker-debuginfo is earlier than 0:1.1.10-14.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41782"/>
      <state state_ref="oval:org.mitre.oval:ste:34956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125758" version="1" comment="pacemaker is earlier than 0:1.1.10-14.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42356"/>
      <state state_ref="oval:org.mitre.oval:ste:34956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125701" version="1" comment="pacemaker-libs-devel is earlier than 0:1.1.10-14.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42648"/>
      <state state_ref="oval:org.mitre.oval:ste:34956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125581" version="1" comment="pacemaker-remote is earlier than 0:1.1.10-14.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41998"/>
      <state state_ref="oval:org.mitre.oval:ste:34956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125397" version="1" comment="pacemaker-doc is earlier than 0:1.1.10-14.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42552"/>
      <state state_ref="oval:org.mitre.oval:ste:34956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123844" version="1" comment="libvirt is earlier than 0:0.10.2-29.el6_5.11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15209"/>
      <state state_ref="oval:org.mitre.oval:ste:34403"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123783" version="1" comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15191"/>
      <state state_ref="oval:org.mitre.oval:ste:34403"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123675" version="1" comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29031"/>
      <state state_ref="oval:org.mitre.oval:ste:34403"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123569" version="1" comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14880"/>
      <state state_ref="oval:org.mitre.oval:ste:34403"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123423" version="1" comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.11" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28971"/>
      <state state_ref="oval:org.mitre.oval:ste:34403"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138389" version="1" comment="glibc-debuginfo is earlier than 0:2.12-1.149.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4398"/>
      <state state_ref="oval:org.mitre.oval:ste:38579"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:138284" version="1" comment="glibc-debuginfo-common is earlier than 0:2.12-1.149.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42178"/>
      <state state_ref="oval:org.mitre.oval:ste:38579"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125232" version="1" comment="glibc-common is earlier than 0:2.12-1.149.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:34612"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125182" version="1" comment="glibc-static is earlier than 0:2.12-1.149.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30224"/>
      <state state_ref="oval:org.mitre.oval:ste:34612"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125145" version="1" comment="glibc is earlier than 0:2.12-1.149.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:34612"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125139" version="1" comment="glibc-utils is earlier than 0:2.12-1.149.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:34612"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125135" version="1" comment="glibc-devel is earlier than 0:2.12-1.149.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:34612"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125086" version="1" comment="glibc-headers is earlier than 0:2.12-1.149.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:34612"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124988" version="1" comment="nscd is earlier than 0:2.12-1.149.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:34612"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123949" version="1" comment="bash is earlier than 0:3.2-33.el5_10.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123900" version="1" comment="bash-doc is earlier than 0:4.2.45-5.el7_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41925"/>
      <state state_ref="oval:org.mitre.oval:ste:33655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123544" version="1" comment="bash is earlier than 0:4.1.2-15.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34343"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123527" version="1" comment="bash is earlier than 0:4.2.45-5.el7_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:33655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123461" version="1" comment="bash-doc is earlier than 0:4.1.2-15.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41925"/>
      <state state_ref="oval:org.mitre.oval:ste:34343"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123086" version="1" comment="bash is earlier than 0:3.2-33.el5_11.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34448"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123170" version="1" comment="xulrunner-devel is earlier than 0:24.8.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:33841"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123084" version="1" comment="firefox is earlier than 0:24.8.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:33981"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123047" version="1" comment="firefox is earlier than 0:24.8.0-2.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:34014"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122891" version="1" comment="firefox is earlier than 0:24.8.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:33841"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122877" version="1" comment="xulrunner-devel is earlier than 0:24.8.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:33779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122875" version="1" comment="xulrunner is earlier than 0:24.8.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:33779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122819" version="1" comment="firefox is earlier than 0:24.8.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:33779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122772" version="1" comment="xulrunner is earlier than 0:24.8.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:33841"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122594" version="1" comment="firefox is earlier than 0:24.8.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:33957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122510" version="1" comment="firefox is earlier than 0:24.8.0-2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:33550"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123152" version="1" comment="thunderbird is earlier than 0:24.8.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:33957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123029" version="1" comment="thunderbird is earlier than 0:24.8.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:34090"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122969" version="1" comment="thunderbird is earlier than 0:24.8.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:33981"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122759" version="1" comment="thunderbird is earlier than 0:24.8.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:33984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123953" version="1" comment="bash is earlier than 0:3.2-33.el5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123932" version="1" comment="bash is earlier than 0:4.1.2-15.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123926" version="1" comment="bash is earlier than 0:4.2.45-5.el7_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3150"/>
      <state state_ref="oval:org.mitre.oval:ste:34132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123825" version="1" comment="bash-doc is earlier than 0:4.2.45-5.el7_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41925"/>
      <state state_ref="oval:org.mitre.oval:ste:34132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123696" version="1" comment="bash-doc is earlier than 0:4.1.2-15.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41925"/>
      <state state_ref="oval:org.mitre.oval:ste:34361"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123818" version="1" comment="jakarta-commons-httpclient is earlier than 1:3.0-7jpp.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29187"/>
      <state state_ref="oval:org.mitre.oval:ste:34275"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123817" version="1" comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-16.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29053"/>
      <state state_ref="oval:org.mitre.oval:ste:34438"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123816" version="1" comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.0-7jpp.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29165"/>
      <state state_ref="oval:org.mitre.oval:ste:34275"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123792" version="1" comment="jakarta-commons-httpclient is earlier than 1:3.1-16.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29187"/>
      <state state_ref="oval:org.mitre.oval:ste:34438"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123791" version="1" comment="jakarta-commons-httpclient-manual is earlier than 1:3.0-7jpp.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29053"/>
      <state state_ref="oval:org.mitre.oval:ste:34275"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123770" version="1" comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-16.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29165"/>
      <state state_ref="oval:org.mitre.oval:ste:34438"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123758" version="1" comment="jakarta-commons-httpclient-manual is earlier than 1:3.1-0.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29053"/>
      <state state_ref="oval:org.mitre.oval:ste:34285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123708" version="1" comment="jakarta-commons-httpclient-demo is earlier than 1:3.0-7jpp.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29059"/>
      <state state_ref="oval:org.mitre.oval:ste:34275"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123604" version="1" comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-0.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29059"/>
      <state state_ref="oval:org.mitre.oval:ste:34285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123283" version="1" comment="jakarta-commons-httpclient-demo is earlier than 1:3.1-16.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29059"/>
      <state state_ref="oval:org.mitre.oval:ste:34438"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123167" version="1" comment="jakarta-commons-httpclient is earlier than 1:3.1-0.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29187"/>
      <state state_ref="oval:org.mitre.oval:ste:34285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122896" version="1" comment="jakarta-commons-httpclient-javadoc is earlier than 1:3.1-0.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29165"/>
      <state state_ref="oval:org.mitre.oval:ste:34285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123831" version="1" comment="procmail is earlier than 0:3.22-17.1.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42185"/>
      <state state_ref="oval:org.mitre.oval:ste:34013"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123631" version="1" comment="procmail is earlier than 0:3.22-25.1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42185"/>
      <state state_ref="oval:org.mitre.oval:ste:34274"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123381" version="1" comment="procmail is earlier than 0:3.22-34.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42185"/>
      <state state_ref="oval:org.mitre.oval:ste:34287"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123250" version="1" comment="procmail is earlier than 0:3.22-17.1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42185"/>
      <state state_ref="oval:org.mitre.oval:ste:34303"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122703" version="1" comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.15" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:33572"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122686" version="1" comment="openssl-perl is earlier than 1:1.0.1e-34.el7_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:33332"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122648" version="1" comment="openssl-libs is earlier than 1:1.0.1e-34.el7_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39297"/>
      <state state_ref="oval:org.mitre.oval:ste:33332"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122626" version="1" comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.15" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:33572"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122570" version="1" comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.15" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:33572"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122547" version="1" comment="openssl is earlier than 0:1.0.1e-16.el6_5.15" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:33572"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122537" version="1" comment="openssl-devel is earlier than 1:1.0.1e-34.el7_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:33332"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122485" version="1" comment="openssl-static is earlier than 1:1.0.1e-34.el7_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:33332"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122367" version="1" comment="openssl is earlier than 1:1.0.1e-34.el7_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:33332"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122651" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122617" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122592" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122553" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122541" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122517" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122498" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122462" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122398" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122357" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122289" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122234" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121990" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121901" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:33386"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121689" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:33675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122516" version="1" comment="389-ds-base is earlier than 0:1.2.11.15-34.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28953"/>
      <state state_ref="oval:org.mitre.oval:ste:33513"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122506" version="1" comment="389-ds-base is earlier than 0:1.3.1.6-26.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28953"/>
      <state state_ref="oval:org.mitre.oval:ste:33645"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122486" version="1" comment="389-ds-base-devel is earlier than 0:1.2.11.15-34.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29162"/>
      <state state_ref="oval:org.mitre.oval:ste:33513"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122405" version="1" comment="389-ds-base-devel is earlier than 0:1.3.1.6-26.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29162"/>
      <state state_ref="oval:org.mitre.oval:ste:33645"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122226" version="1" comment="389-ds-base-libs is earlier than 0:1.2.11.15-34.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28949"/>
      <state state_ref="oval:org.mitre.oval:ste:33513"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121859" version="1" comment="389-ds-base-libs is earlier than 0:1.3.1.6-26.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28949"/>
      <state state_ref="oval:org.mitre.oval:ste:33645"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137992" version="1" comment="luci is earlier than 0:0.26.0-63.el6.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14950"/>
      <state state_ref="oval:org.mitre.oval:ste:38491"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124900" version="1" comment="luci is earlier than 0:0.26.0-63.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14950"/>
      <state state_ref="oval:org.mitre.oval:ste:34570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123079" version="1" comment="nscd is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123073" version="1" comment="glibc-headers is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123071" version="1" comment="nscd is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123069" version="1" comment="glibc-headers is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123068" version="1" comment="glibc-devel is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123059" version="1" comment="glibc-devel is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123035" version="1" comment="glibc is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123024" version="1" comment="glibc-devel is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:123014" version="1" comment="glibc-static is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30224"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122956" version="1" comment="glibc is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122938" version="1" comment="glibc-utils is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122909" version="1" comment="nscd is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122887" version="1" comment="glibc is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122779" version="1" comment="glibc-utils is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122739" version="1" comment="glibc-common is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122669" version="1" comment="glibc-utils is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122535" version="1" comment="glibc-common is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122432" version="1" comment="glibc-headers is earlier than 0:2.17-55.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:33765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122402" version="1" comment="glibc-static is earlier than 0:2.12-1.132.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30224"/>
      <state state_ref="oval:org.mitre.oval:ste:33333"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122380" version="1" comment="glibc-common is earlier than 0:2.5-118.el5_10.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:33904"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122600" version="1" comment="flash-plugin is earlier than 0:11.2.202.400-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:33310"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121704" version="1" comment="flash-plugin is earlier than 0:11.2.202.400-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:33468"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122650" version="1" comment="tomcat6 is earlier than 0:6.0.24-78.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29276"/>
      <state state_ref="oval:org.mitre.oval:ste:32960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122649" version="1" comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-78.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29382"/>
      <state state_ref="oval:org.mitre.oval:ste:32960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122586" version="1" comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-78.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29264"/>
      <state state_ref="oval:org.mitre.oval:ste:32960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122562" version="1" comment="tomcat6-javadoc is earlier than 0:6.0.24-78.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28454"/>
      <state state_ref="oval:org.mitre.oval:ste:32960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122556" version="1" comment="tomcat6-webapps is earlier than 0:6.0.24-78.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29371"/>
      <state state_ref="oval:org.mitre.oval:ste:32960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122520" version="1" comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-78.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29298"/>
      <state state_ref="oval:org.mitre.oval:ste:32960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122501" version="1" comment="tomcat6-admin-webapps is earlier than 0:6.0.24-78.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28477"/>
      <state state_ref="oval:org.mitre.oval:ste:32960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122470" version="1" comment="tomcat6-lib is earlier than 0:6.0.24-78.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29391"/>
      <state state_ref="oval:org.mitre.oval:ste:32960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122327" version="1" comment="tomcat6-docs-webapp is earlier than 0:6.0.24-78.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29374"/>
      <state state_ref="oval:org.mitre.oval:ste:32960"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122687" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122671" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122656" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122629" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122607" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122596" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122566" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122552" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122509" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122347" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122275" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122192" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122123" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121907" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.7-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:33188"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121790" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.7-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:33472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122456" version="1" comment="samba4-client is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28823"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122447" version="1" comment="samba4-pidl is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28846"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122317" version="1" comment="samba4-libs is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28992"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122311" version="1" comment="samba4-common is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29227"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122296" version="1" comment="samba4-devel is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29269"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122288" version="1" comment="samba4 is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29063"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122245" version="1" comment="samba4-test is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28805"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122214" version="1" comment="samba4-swat is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29252"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122142" version="1" comment="samba4-python is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29198"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121984" version="1" comment="samba4-dc-libs is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28905"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121983" version="1" comment="samba4-winbind is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28782"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121966" version="1" comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29221"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121933" version="1" comment="samba4-dc is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28292"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121777" version="1" comment="samba4-winbind-clients is earlier than 0:4.0.0-63.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29244"/>
      <state state_ref="oval:org.mitre.oval:ste:33707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122529" version="1" comment="php-fpm is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29228"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122521" version="1" comment="php-bcmath is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122491" version="1" comment="php-imap is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122483" version="1" comment="php-enchant is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122478" version="1" comment="php-pgsql is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122469" version="1" comment="php-intl is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122450" version="1" comment="php-xml is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122446" version="1" comment="php-process is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122442" version="1" comment="php53-dba is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28950"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122423" version="1" comment="php-soap is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122422" version="1" comment="php53-bcmath is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29087"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122396" version="1" comment="php-common is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122386" version="1" comment="php53-process is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29375"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122385" version="1" comment="php53-gd is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29626"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122383" version="1" comment="php53-ldap is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29602"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122382" version="1" comment="php-recode is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122373" version="1" comment="php-xmlrpc is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122364" version="1" comment="php53-devel is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29547"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122355" version="1" comment="php-zts is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29304"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122353" version="1" comment="php-mbstring is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122302" version="1" comment="php53-pgsql is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29505"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122300" version="1" comment="php53-intl is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29195"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122293" version="1" comment="php-ldap is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122243" version="1" comment="php53-odbc is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29337"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122240" version="1" comment="php-cli is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122239" version="1" comment="php-odbc is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122231" version="1" comment="php-snmp is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122213" version="1" comment="php53-common is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29562"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122205" version="1" comment="php53-mbstring is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29008"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122144" version="1" comment="php is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122138" version="1" comment="php53-xml is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29235"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122090" version="1" comment="php53-mysql is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29022"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122085" version="1" comment="php53-imap is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29568"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122067" version="1" comment="php-dba is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122063" version="1" comment="php53-snmp is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29427"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122020" version="1" comment="php-devel is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122000" version="1" comment="php-pspell is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121951" version="1" comment="php-mysql is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121863" version="1" comment="php53-soap is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29455"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121848" version="1" comment="php53 is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29556"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121844" version="1" comment="php53-pspell is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29208"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121820" version="1" comment="php53-pdo is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29253"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121691" version="1" comment="php-embedded is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121548" version="1" comment="php-tidy is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28881"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121534" version="1" comment="php-pdo is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121529" version="1" comment="php-gd is earlier than 0:5.3.3-27.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:33548"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121506" version="1" comment="php53-cli is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28902"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121502" version="1" comment="php53-xmlrpc is earlier than 0:5.3.3-23.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29475"/>
      <state state_ref="oval:org.mitre.oval:ste:33672"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121445" version="1" comment="dracut-generic is earlier than 0:004-336.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41656"/>
      <state state_ref="oval:org.mitre.oval:ste:33255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121357" version="1" comment="dracut-fips-aesni is earlier than 0:004-336.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:40984"/>
      <state state_ref="oval:org.mitre.oval:ste:33255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121336" version="1" comment="dracut-tools is earlier than 0:004-336.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41802"/>
      <state state_ref="oval:org.mitre.oval:ste:33255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121314" version="1" comment="dracut-kernel is earlier than 0:004-336.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41286"/>
      <state state_ref="oval:org.mitre.oval:ste:33255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121261" version="1" comment="dracut-fips is earlier than 0:004-336.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41207"/>
      <state state_ref="oval:org.mitre.oval:ste:33255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121129" version="1" comment="dracut-caps is earlier than 0:004-336.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41785"/>
      <state state_ref="oval:org.mitre.oval:ste:33255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121027" version="1" comment="dracut-network is earlier than 0:004-336.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41353"/>
      <state state_ref="oval:org.mitre.oval:ste:33255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120859" version="1" comment="dracut is earlier than 0:004-336.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41533"/>
      <state state_ref="oval:org.mitre.oval:ste:33255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121453" version="1" comment="glibc-common is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:33422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121434" version="1" comment="glibc-headers is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:33422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121418" version="1" comment="glibc is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:33422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121335" version="1" comment="glibc-utils is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:33422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121239" version="1" comment="glibc-static is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30121"/>
      <state state_ref="oval:org.mitre.oval:ste:33422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121079" version="1" comment="nscd is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:33422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120736" version="1" comment="glibc-devel is earlier than 0:2.12-1.132.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:33422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121425" version="1" comment="busybox-petitboot is earlier than 1:1.15.1-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29516"/>
      <state state_ref="oval:org.mitre.oval:ste:33480"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121374" version="1" comment="busybox is earlier than 1:1.15.1-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14087"/>
      <state state_ref="oval:org.mitre.oval:ste:33480"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121451" version="1" comment="openssh-server is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14544"/>
      <state state_ref="oval:org.mitre.oval:ste:33138"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121417" version="1" comment="openssh-clients is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14409"/>
      <state state_ref="oval:org.mitre.oval:ste:33138"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121375" version="1" comment="openssh-askpass is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14577"/>
      <state state_ref="oval:org.mitre.oval:ste:33138"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121047" version="1" comment="openssh-ldap is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29531"/>
      <state state_ref="oval:org.mitre.oval:ste:33138"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120970" version="1" comment="openssh is earlier than 0:5.3p1-94.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14581"/>
      <state state_ref="oval:org.mitre.oval:ste:33138"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120715" version="1" comment="pam_ssh_agent_auth is earlier than 0:0.9.3-94.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29349"/>
      <state state_ref="oval:org.mitre.oval:ste:33158"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121413" version="1" comment="sudo-devel is earlier than 0:1.8.6p3-12.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41539"/>
      <state state_ref="oval:org.mitre.oval:ste:33477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121277" version="1" comment="sudo is earlier than 0:1.8.6p3-12.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41703"/>
      <state state_ref="oval:org.mitre.oval:ste:33477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:125231" version="1" comment="flash-plugin is earlier than 0:11.2.202.411-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:34812"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:124405" version="1" comment="flash-plugin is earlier than 0:11.2.202.411-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:34543"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121455" version="1" comment="kernel-kdump is earlier than 0:2.6.32-431.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:33238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121408" version="1" comment="kernel-firmware is earlier than 0:2.6.32-431.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:33238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121345" version="1" comment="perf is earlier than 0:2.6.32-431.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:33238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121246" version="1" comment="kernel-headers is earlier than 0:2.6.32-431.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:33238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121221" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-431.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:33238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120938" version="1" comment="kernel-devel is earlier than 0:2.6.32-431.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:33238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120863" version="1" comment="kernel-doc is earlier than 0:2.6.32-431.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:33238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120839" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-431.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:33238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120724" version="1" comment="kernel is earlier than 0:2.6.32-431.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:33238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120544" version="1" comment="kernel-debug is earlier than 0:2.6.32-431.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:33238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122672" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122662" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122622" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122550" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29107"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122508" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122504" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29107"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122424" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122406" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122312" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122155" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:33174"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122134" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:122122" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:33654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121432" version="1" comment="samba4-client is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28823"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121415" version="1" comment="samba4-winbind-clients is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29244"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121414" version="1" comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29221"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121411" version="1" comment="samba4-libs is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28992"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121360" version="1" comment="samba4-dc is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28292"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121344" version="1" comment="samba4 is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29063"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121330" version="1" comment="samba4-dc-libs is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28905"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121315" version="1" comment="samba4-swat is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29252"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121263" version="1" comment="samba4-devel is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29269"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121251" version="1" comment="samba4-common is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29227"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121060" version="1" comment="samba4-winbind is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28782"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120829" version="1" comment="samba4-pidl is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28846"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120730" version="1" comment="samba4-test is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28805"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120504" version="1" comment="samba4-python is earlier than 0:4.0.0-58.el6.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29198"/>
      <state state_ref="oval:org.mitre.oval:ste:32974"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121389" version="1" comment="coreutils is earlier than 0:8.4-31.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3720"/>
      <state state_ref="oval:org.mitre.oval:ste:33280"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121339" version="1" comment="coreutils-libs is earlier than 0:8.4-31.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:41646"/>
      <state state_ref="oval:org.mitre.oval:ste:33280"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121501" version="1" comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29639"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121456" version="1" comment="kernel-debug is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121431" version="1" comment="kernel-firmware is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121300" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121291" version="1" comment="kernel is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121253" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121234" version="1" comment="perf is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121181" version="1" comment="kernel-headers is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121145" version="1" comment="python-perf is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121010" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121002" version="1" comment="kernel-kdump is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120933" version="1" comment="kernel-devel is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120822" version="1" comment="kernel-doc is earlier than 0:2.6.32-431.23.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:32582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121466" version="1" comment="libsmbclient is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15389"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121447" version="1" comment="samba-winbind-clients is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29486"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121406" version="1" comment="samba-winbind is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29389"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121366" version="1" comment="samba-domainjoin-gui is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121313" version="1" comment="samba-common is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14032"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121280" version="1" comment="libsmbclient-devel is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121199" version="1" comment="samba-swat is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121097" version="1" comment="samba is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:121067" version="1" comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28660"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120977" version="1" comment="samba-doc is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29416"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120833" version="1" comment="samba-winbind-devel is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29445"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:120648" version="1" comment="samba-client is earlier than 0:3.6.9-164.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:33345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116305" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116089" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116084" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116078" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37441"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116062" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115789" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115505" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37441"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115401" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.81-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:32037"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115370" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115363" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115322" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115315" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.81-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:31792"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116354" version="1" comment="httpd-devel is earlier than 0:2.2.15-31.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:31991"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116334" version="1" comment="httpd-tools is earlier than 0:2.2.15-31.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29273"/>
      <state state_ref="oval:org.mitre.oval:ste:32006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116330" version="1" comment="mod_ssl is earlier than 1:2.2.15-31.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:31706"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116323" version="1" comment="httpd-manual is earlier than 0:2.2.15-31.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:31991"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116289" version="1" comment="mod_ssl is earlier than 1:2.2.15-31.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:32021"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116271" version="1" comment="mod_ssl is earlier than 1:2.2.3-87.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:31977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116217" version="1" comment="httpd is earlier than 0:2.2.15-31.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:31991"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116210" version="1" comment="httpd-devel is earlier than 0:2.2.3-87.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:31982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116201" version="1" comment="httpd-manual is earlier than 0:2.2.3-87.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:31982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116196" version="1" comment="mod_ssl is earlier than 1:2.2.3-87.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:32177"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116175" version="1" comment="httpd is earlier than 0:2.2.3-87.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:31982"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116136" version="1" comment="httpd-devel is earlier than 0:2.2.15-31.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:32006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116114" version="1" comment="httpd-manual is earlier than 0:2.2.3-87.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:32169"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115938" version="1" comment="httpd is earlier than 0:2.2.3-87.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:32169"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115768" version="1" comment="httpd-tools is earlier than 0:2.2.15-31.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29273"/>
      <state state_ref="oval:org.mitre.oval:ste:31991"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115650" version="1" comment="httpd is earlier than 0:2.2.15-31.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:32006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115382" version="1" comment="httpd-manual is earlier than 0:2.2.15-31.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:32006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115372" version="1" comment="httpd-devel is earlier than 0:2.2.3-87.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:32169"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116205" version="2" comment="lzo is earlier than 0:2.06-6.el7_0.2" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38795"/>
      <state state_ref="oval:org.mitre.oval:ste:31870"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116180" version="2" comment="lzo is earlier than 0:2.03-3.1.el6_5.1" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38795"/>
      <state state_ref="oval:org.mitre.oval:ste:31348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116177" version="2" comment="lzo-minilzo is earlier than 0:2.03-3.1.el6_5.1" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38895"/>
      <state state_ref="oval:org.mitre.oval:ste:31348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116081" version="2" comment="lzo-devel is earlier than 0:2.03-3.1.el6_5.1" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39487"/>
      <state state_ref="oval:org.mitre.oval:ste:31348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115769" version="2" comment="lzo-minilzo is earlier than 0:2.06-6.el7_0.2" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38895"/>
      <state state_ref="oval:org.mitre.oval:ste:31870"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115695" version="2" comment="lzo-devel is earlier than 0:2.06-6.el7_0.2" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39487"/>
      <state state_ref="oval:org.mitre.oval:ste:31870"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135338" version="1" comment="kernel-debuginfo-common-i686 is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42774"/>
      <state state_ref="oval:org.mitre.oval:ste:37373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135260" version="1" comment="kernel-debug-debuginfo is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42590"/>
      <state state_ref="oval:org.mitre.oval:ste:37373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135131" version="1" comment="python-perf-debuginfo is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43043"/>
      <state state_ref="oval:org.mitre.oval:ste:37373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:135106" version="1" comment="kernel-debuginfo is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42117"/>
      <state state_ref="oval:org.mitre.oval:ste:37373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:134491" version="1" comment="perf-debuginfo is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42724"/>
      <state state_ref="oval:org.mitre.oval:ste:37373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:134423" version="1" comment="kernel-debuginfo-common-x86_64 is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42704"/>
      <state state_ref="oval:org.mitre.oval:ste:37373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116372" version="1" comment="kernel-devel is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:31912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116371" version="1" comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38242"/>
      <state state_ref="oval:org.mitre.oval:ste:31912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116314" version="1" comment="kernel is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:31912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116214" version="1" comment="perf is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:31912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115972" version="1" comment="python-perf is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:31912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115967" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:31912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115956" version="1" comment="kernel-doc is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:31912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115732" version="1" comment="kernel-debug is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:31912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115677" version="1" comment="kernel-firmware is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:31912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115478" version="1" comment="kernel-headers is earlier than 0:2.6.32-431.20.5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38456"/>
      <state state_ref="oval:org.mitre.oval:ste:31912"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116211" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:31388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116193" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37884"/>
      <state state_ref="oval:org.mitre.oval:ste:31743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116192" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:31388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116179" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37884"/>
      <state state_ref="oval:org.mitre.oval:ste:31388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116166" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:31600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116148" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:31743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116146" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38018"/>
      <state state_ref="oval:org.mitre.oval:ste:31743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116140" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-6.1.13.4.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37884"/>
      <state state_ref="oval:org.mitre.oval:ste:31600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116107" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:31388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116093" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:31743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116029" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38018"/>
      <state state_ref="oval:org.mitre.oval:ste:31388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115888" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-6.1.13.4.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:31743"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115881" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-6.1.13.4.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:31600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115804" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-6.1.13.4.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:31600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115700" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-6.1.13.4.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38018"/>
      <state state_ref="oval:org.mitre.oval:ste:31600"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116208" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38120"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116159" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38120"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116130" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38181"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116045" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116028" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115996" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115979" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.65-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:31957"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115925" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115810" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115721" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38181"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115708" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115380" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.65-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:31962"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115998" version="1" comment="libsmbclient-devel is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115908" version="1" comment="libsmbclient is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37433"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115904" version="1" comment="samba-winbind-clients is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38277"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115866" version="1" comment="samba3x-client is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14854"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115854" version="1" comment="samba-winbind is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29389"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115828" version="1" comment="samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15095"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115827" version="1" comment="samba3x-doc is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14991"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115794" version="1" comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28660"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115752" version="1" comment="samba3x-common is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14673"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115719" version="1" comment="samba-winbind-devel is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29445"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115699" version="1" comment="samba-doc is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37787"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115671" version="1" comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15239"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115588" version="1" comment="samba is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115545" version="1" comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15045"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115415" version="1" comment="samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115293" version="1" comment="samba3x is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15124"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115213" version="1" comment="samba3x-swat is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15202"/>
      <state state_ref="oval:org.mitre.oval:ste:31400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115108" version="1" comment="samba-client is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115089" version="1" comment="samba-swat is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115002" version="1" comment="samba-common is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38329"/>
      <state state_ref="oval:org.mitre.oval:ste:31739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116333" version="1" comment="firefox is earlier than 0:24.7.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:32072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116303" version="1" comment="firefox is earlier than 0:24.7.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:32159"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116256" version="1" comment="firefox is earlier than 0:24.7.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31838"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116167" version="1" comment="firefox is earlier than 0:24.7.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31784"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116099" version="1" comment="firefox is earlier than 0:24.7.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31874"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116085" version="1" comment="firefox is earlier than 0:24.7.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115931" version="1" comment="xulrunner-devel is earlier than 0:24.7.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:31784"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115784" version="1" comment="xulrunner is earlier than 0:24.7.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:31784"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115740" version="1" comment="xulrunner is earlier than 0:24.7.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:31643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115371" version="1" comment="xulrunner-devel is earlier than 0:24.7.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:31643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115927" version="1" comment="lzo is earlier than 0:2.06-6.el7_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38885"/>
      <state state_ref="oval:org.mitre.oval:ste:31569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115897" version="1" comment="lzo is earlier than 0:2.03-3.1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38885"/>
      <state state_ref="oval:org.mitre.oval:ste:31760"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115880" version="1" comment="lzo-minilzo is earlier than 0:2.06-6.el7_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39257"/>
      <state state_ref="oval:org.mitre.oval:ste:31569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115839" version="1" comment="lzo-devel is earlier than 0:2.06-6.el7_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39419"/>
      <state state_ref="oval:org.mitre.oval:ste:31569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115746" version="1" comment="lzo-devel is earlier than 0:2.03-3.1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39419"/>
      <state state_ref="oval:org.mitre.oval:ste:31760"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115694" version="1" comment="lzo-minilzo is earlier than 0:2.03-3.1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39257"/>
      <state state_ref="oval:org.mitre.oval:ste:31760"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116066" version="1" comment="flash-plugin is earlier than 0:11.2.202.394-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116002" version="1" comment="flash-plugin is earlier than 0:11.2.202.394-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31880"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115756" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:31788"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115697" version="1" comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28988"/>
      <state state_ref="oval:org.mitre.oval:ste:31788"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115503" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37253"/>
      <state state_ref="oval:org.mitre.oval:ste:31788"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115384" version="1" comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37800"/>
      <state state_ref="oval:org.mitre.oval:ste:31788"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114605" version="1" comment="mod_wsgi is earlier than 0:3.2-6.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38924"/>
      <state state_ref="oval:org.mitre.oval:ste:31679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115565" version="1" comment="dovecot-pigeonhole is earlier than 1:2.0.9-7.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35834"/>
      <state state_ref="oval:org.mitre.oval:ste:31639"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115504" version="1" comment="dovecot is earlier than 1:2.2.10-4.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3572"/>
      <state state_ref="oval:org.mitre.oval:ste:31603"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115468" version="1" comment="dovecot-devel is earlier than 1:2.0.9-7.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4212"/>
      <state state_ref="oval:org.mitre.oval:ste:31639"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115465" version="1" comment="dovecot is earlier than 1:2.0.9-7.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3572"/>
      <state state_ref="oval:org.mitre.oval:ste:31639"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115453" version="1" comment="dovecot-mysql is earlier than 1:2.2.10-4.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29698"/>
      <state state_ref="oval:org.mitre.oval:ste:31603"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115404" version="1" comment="dovecot-pigeonhole is earlier than 1:2.2.10-4.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35834"/>
      <state state_ref="oval:org.mitre.oval:ste:31603"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115161" version="1" comment="dovecot-pgsql is earlier than 1:2.2.10-4.el7_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30241"/>
      <state state_ref="oval:org.mitre.oval:ste:31603"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115126" version="1" comment="dovecot-pgsql is earlier than 1:2.0.9-7.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30241"/>
      <state state_ref="oval:org.mitre.oval:ste:31639"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114827" version="1" comment="dovecot-mysql is earlier than 1:2.0.9-7.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29698"/>
      <state state_ref="oval:org.mitre.oval:ste:31639"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115431" version="1" comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28988"/>
      <state state_ref="oval:org.mitre.oval:ste:31513"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115375" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37253"/>
      <state state_ref="oval:org.mitre.oval:ste:31513"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115261" version="1" comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37800"/>
      <state state_ref="oval:org.mitre.oval:ste:31513"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115065" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:31513"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116308" version="1" comment="nss-tools is earlier than 0:3.16.1-4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:31892"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116284" version="1" comment="nspr is earlier than 0:4.10.6-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:31713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116255" version="1" comment="nss-devel is earlier than 0:3.16.1-4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:31892"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116195" version="1" comment="nss-sysinit is earlier than 0:3.16.1-4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38151"/>
      <state state_ref="oval:org.mitre.oval:ste:31892"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116150" version="1" comment="nss is earlier than 0:3.16.1-4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:36815"/>
      <state state_ref="oval:org.mitre.oval:ste:31892"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116059" version="1" comment="nss-util is earlier than 0:3.16.1-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:31811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115997" version="1" comment="nss-pkcs11-devel is earlier than 0:3.16.1-4.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:31892"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115945" version="1" comment="nss-util-devel is earlier than 0:3.16.1-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:31811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115335" version="1" comment="nspr-devel is earlier than 0:4.10.6-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:31713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116259" version="2" comment="samba3x-doc is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14991"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116253" version="2" comment="samba3x-client is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14854"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116223" version="2" comment="samba is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116200" version="2" comment="samba-winbind-clients is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38277"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116190" version="2" comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15045"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116128" version="2" comment="samba-domainjoin-gui is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116106" version="2" comment="samba-swat is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116097" version="2" comment="samba-doc is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37787"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116076" version="2" comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15239"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116003" version="2" comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28660"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115986" version="2" comment="samba-winbind is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29389"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115965" version="2" comment="samba3x-winbind is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15095"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115954" version="2" comment="samba-client is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115949" version="2" comment="libsmbclient-devel is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115887" version="2" comment="libsmbclient is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37433"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115686" version="2" comment="samba3x-swat is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15202"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115675" version="2" comment="samba-winbind-devel is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29445"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115479" version="2" comment="samba3x is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15124"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115374" version="2" comment="samba3x-common is earlier than 0:3.6.6-0.140.el5_10" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14673"/>
      <state state_ref="oval:org.mitre.oval:ste:31718"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115270" version="2" comment="samba-common is earlier than 0:3.6.9-169.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38329"/>
      <state state_ref="oval:org.mitre.oval:ste:31373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116250" version="2" comment="tomcat6-lib is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29391"/>
      <state state_ref="oval:org.mitre.oval:ste:31935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116171" version="2" comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37718"/>
      <state state_ref="oval:org.mitre.oval:ste:31935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116119" version="2" comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29264"/>
      <state state_ref="oval:org.mitre.oval:ste:31935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116072" version="2" comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29382"/>
      <state state_ref="oval:org.mitre.oval:ste:31935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116001" version="2" comment="tomcat6-webapps is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29371"/>
      <state state_ref="oval:org.mitre.oval:ste:31935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115868" version="2" comment="tomcat6 is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38013"/>
      <state state_ref="oval:org.mitre.oval:ste:31935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115706" version="2" comment="tomcat6-docs-webapp is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29374"/>
      <state state_ref="oval:org.mitre.oval:ste:31935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115496" version="2" comment="tomcat6-javadoc is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28454"/>
      <state state_ref="oval:org.mitre.oval:ste:31935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115343" version="2" comment="tomcat6-admin-webapps is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28477"/>
      <state state_ref="oval:org.mitre.oval:ste:31935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115603" version="1" comment="kernel-kdump is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37985"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115580" version="1" comment="perf is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115575" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38382"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115563" version="1" comment="kernel-firmware is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115542" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115491" version="1" comment="python-perf is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115456" version="1" comment="kernel-debug is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115387" version="1" comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38242"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115337" version="1" comment="kernel-devel is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115180" version="1" comment="kernel is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115177" version="1" comment="kernel-headers is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38456"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115137" version="1" comment="kernel-doc is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115074" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-431.20.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:31655"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114826" version="1" comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:31529"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114755" version="1" comment="openssl is earlier than 0:1.0.1e-16.el6_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:31529"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114643" version="1" comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1005"/>
      <state state_ref="oval:org.mitre.oval:ste:31529"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113928" version="1" comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.14" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:31529"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114873" version="1" comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29031"/>
      <state state_ref="oval:org.mitre.oval:ste:31300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114793" version="1" comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15191"/>
      <state state_ref="oval:org.mitre.oval:ste:31300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114742" version="1" comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37751"/>
      <state state_ref="oval:org.mitre.oval:ste:31300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114687" version="1" comment="libvirt is earlier than 0:0.10.2-29.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15209"/>
      <state state_ref="oval:org.mitre.oval:ste:31300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114344" version="1" comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28971"/>
      <state state_ref="oval:org.mitre.oval:ste:31300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115943" version="1" comment="tomcat6-lib is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29391"/>
      <state state_ref="oval:org.mitre.oval:ste:31591"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115920" version="1" comment="tomcat6 is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38013"/>
      <state state_ref="oval:org.mitre.oval:ste:31591"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115879" version="1" comment="tomcat6-docs-webapp is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29374"/>
      <state state_ref="oval:org.mitre.oval:ste:31591"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115736" version="1" comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37718"/>
      <state state_ref="oval:org.mitre.oval:ste:31591"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115510" version="1" comment="tomcat6-admin-webapps is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28477"/>
      <state state_ref="oval:org.mitre.oval:ste:31591"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115266" version="1" comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29382"/>
      <state state_ref="oval:org.mitre.oval:ste:31591"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115110" version="1" comment="tomcat6-webapps is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29371"/>
      <state state_ref="oval:org.mitre.oval:ste:31591"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115099" version="1" comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29264"/>
      <state state_ref="oval:org.mitre.oval:ste:31591"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114945" version="1" comment="tomcat6-javadoc is earlier than 0:6.0.24-72.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28454"/>
      <state state_ref="oval:org.mitre.oval:ste:31591"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114160" version="1" comment="firefox is earlier than 0:24.5.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30744"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114141" version="1" comment="firefox is earlier than 0:24.5.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30786"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113595" version="1" comment="firefox is earlier than 0:24.5.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30909"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113371" version="1" comment="firefox is earlier than 0:24.5.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30529"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115747" version="1" comment="flash-plugin is earlier than 0:11.2.202.378-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31899"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115295" version="1" comment="flash-plugin is earlier than 0:11.2.202.378-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31913"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114360" version="1" comment="thunderbird is earlier than 0:24.5.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30744"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114348" version="1" comment="thunderbird is earlier than 0:24.5.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30909"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114036" version="1" comment="thunderbird is earlier than 0:24.5.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30786"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113987" version="1" comment="thunderbird is earlier than 0:24.5.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30529"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116162" version="1" comment="thunderbird is earlier than 0:24.7.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:32159"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116061" version="1" comment="thunderbird is earlier than 0:24.7.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:31838"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116050" version="1" comment="thunderbird is earlier than 0:24.7.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:31874"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116004" version="1" comment="thunderbird is earlier than 0:24.7.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:32072"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114787" version="1" comment="libcurl is earlier than 0:7.19.7-37.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28912"/>
      <state state_ref="oval:org.mitre.oval:ste:31261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114569" version="1" comment="libcurl-devel is earlier than 0:7.19.7-37.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28736"/>
      <state state_ref="oval:org.mitre.oval:ste:31261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114394" version="1" comment="curl is earlier than 0:7.19.7-37.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37842"/>
      <state state_ref="oval:org.mitre.oval:ste:31261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114414" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114392" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37577"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114373" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114370" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114358" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114331" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114294" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114275" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114061" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37577"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114004" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37509"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113923" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113837" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113811" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113772" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.6-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:31200"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113443" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.6-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37509"/>
      <state state_ref="oval:org.mitre.oval:ste:30470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115390" version="1" comment="python-jinja2 is earlier than 0:2.2.1-2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38814"/>
      <state state_ref="oval:org.mitre.oval:ste:31226"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114364" version="1" comment="flash-plugin is earlier than 0:11.2.202.359-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31265"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113835" version="1" comment="flash-plugin is earlier than 0:11.2.202.359-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31205"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137833" version="1" comment="openssl-debuginfo is earlier than 0:1.0.1e-16.el6_5.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43044"/>
      <state state_ref="oval:org.mitre.oval:ste:38418"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113774" version="1" comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:31018"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113696" version="1" comment="openssl is earlier than 0:1.0.1e-16.el6_5.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:31018"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113590" version="1" comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1005"/>
      <state state_ref="oval:org.mitre.oval:ste:31018"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113554" version="1" comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:31018"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115597" version="1" comment="thunderbird is earlier than 0:24.6.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:31290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115511" version="1" comment="thunderbird is earlier than 0:24.6.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30851"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115386" version="1" comment="thunderbird is earlier than 0:24.6.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115066" version="1" comment="thunderbird is earlier than 0:24.6.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:31822"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114053" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.55-2.4.7.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:30932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114042" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.55-2.4.7.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:30932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113964" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.55-2.4.7.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:30932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113828" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.55-2.4.7.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:30932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113713" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.55-2.4.7.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:30932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114013" version="1" comment="flash-plugin is earlier than 0:11.2.202.356-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:30308"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114008" version="1" comment="flash-plugin is earlier than 0:11.2.202.356-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:31052"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116147" version="2" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:31057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116139" version="2" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:31057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116095" version="2" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:31057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116052" version="2" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:31932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116039" version="2" comment="java-1.7.0-openjdk-headless is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38588"/>
      <state state_ref="oval:org.mitre.oval:ste:31932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116030" version="2" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:31057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115985" version="2" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:31932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115982" version="2" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el6_5" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:31057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115867" version="2" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:31932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115782" version="2" comment="java-1.7.0-openjdk-accessibility is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39364"/>
      <state state_ref="oval:org.mitre.oval:ste:31932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115765" version="2" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:31932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115519" version="2" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:31932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114378" version="1" comment="kernel-debug is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114366" version="1" comment="kernel-doc is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114362" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38382"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114335" version="1" comment="kernel-firmware is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114319" version="1" comment="kernel-devel is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114291" version="1" comment="kernel-kdump is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37985"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114289" version="1" comment="kernel-headers is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38456"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114287" version="1" comment="perf is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114069" version="1" comment="kernel is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113901" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113695" version="1" comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38242"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113630" version="1" comment="python-perf is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113389" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-431.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:30850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114062" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37441"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114032" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114016" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114000" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113988" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113879" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113867" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113842" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113781" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113722" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113666" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.75-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37441"/>
      <state state_ref="oval:org.mitre.oval:ste:31149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113239" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.75-1jpp.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:31127"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114772" version="1" comment="gnutls-utils is earlier than 0:2.8.5-14.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15003"/>
      <state state_ref="oval:org.mitre.oval:ste:31128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114649" version="1" comment="gnutls-devel is earlier than 0:2.8.5-14.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14558"/>
      <state state_ref="oval:org.mitre.oval:ste:31128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114617" version="1" comment="gnutls-guile is earlier than 0:2.8.5-14.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28427"/>
      <state state_ref="oval:org.mitre.oval:ste:31128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114542" version="1" comment="gnutls is earlier than 0:2.8.5-14.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14386"/>
      <state state_ref="oval:org.mitre.oval:ste:31128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114399" version="1" comment="squid is earlier than 7:3.1.10-20.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14403"/>
      <state state_ref="oval:org.mitre.oval:ste:31566"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113976" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113955" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38181"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113949" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113941" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113900" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113802" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113785" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113657" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38120"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113612" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.55-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38120"/>
      <state state_ref="oval:org.mitre.oval:ste:30835"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113525" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113277" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113074" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.55-1jpp.2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38181"/>
      <state state_ref="oval:org.mitre.oval:ste:30855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114072" version="1" comment="tomcat6-lib is earlier than 0:6.0.24-64.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29391"/>
      <state state_ref="oval:org.mitre.oval:ste:30885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113961" version="1" comment="tomcat6-admin-webapps is earlier than 0:6.0.24-64.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28477"/>
      <state state_ref="oval:org.mitre.oval:ste:30885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113926" version="1" comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-64.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37718"/>
      <state state_ref="oval:org.mitre.oval:ste:30885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113917" version="1" comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-64.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29264"/>
      <state state_ref="oval:org.mitre.oval:ste:30885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113911" version="1" comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-64.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29382"/>
      <state state_ref="oval:org.mitre.oval:ste:30885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113853" version="1" comment="tomcat6 is earlier than 0:6.0.24-64.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38013"/>
      <state state_ref="oval:org.mitre.oval:ste:30885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113834" version="1" comment="tomcat6-javadoc is earlier than 0:6.0.24-64.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28454"/>
      <state state_ref="oval:org.mitre.oval:ste:30885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113816" version="1" comment="tomcat6-docs-webapp is earlier than 0:6.0.24-64.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29374"/>
      <state state_ref="oval:org.mitre.oval:ste:30885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113671" version="1" comment="tomcat6-webapps is earlier than 0:6.0.24-64.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29371"/>
      <state state_ref="oval:org.mitre.oval:ste:30885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114381" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38523"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114372" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114359" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114333" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38523"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114304" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38202"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114256" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38097"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114248" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114217" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114189" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114111" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38202"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114046" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.16.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:31238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113950" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113822" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113426" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113406" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.16.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38097"/>
      <state state_ref="oval:org.mitre.oval:ste:31295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114057" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38018"/>
      <state state_ref="oval:org.mitre.oval:ste:31006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114041" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:30570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114024" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:30570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113912" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-5.1.13.3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:31006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113896" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37884"/>
      <state state_ref="oval:org.mitre.oval:ste:30570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113861" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-5.1.13.3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37884"/>
      <state state_ref="oval:org.mitre.oval:ste:31006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113830" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:30570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113683" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-5.1.13.3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:31006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113650" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-5.1.13.3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:31006"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113056" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-5.1.13.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38018"/>
      <state state_ref="oval:org.mitre.oval:ste:30570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115995" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:31952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115958" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:31952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115926" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:31952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115834" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:30977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115814" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:30977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115800" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:31952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115753" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:30977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115725" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:30977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115715" version="1" comment="java-1.7.0-openjdk-headless is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38823"/>
      <state state_ref="oval:org.mitre.oval:ste:30977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115698" version="1" comment="java-1.7.0-openjdk-accessibility is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:39184"/>
      <state state_ref="oval:org.mitre.oval:ste:30977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115373" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.65-2.5.1.2.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:30977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115329" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.65-2.5.1.2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:31952"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141011" version="1" comment="flash-plugin is earlier than 0:11.2.202.350-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:39351"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113518" version="1" comment="flash-plugin is earlier than 0:11.2.202.350-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:30082"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114443" version="1" comment="libxml2 is earlier than 0:2.7.6-14.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:31201"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114393" version="1" comment="libxml2-static is earlier than 0:2.7.6-14.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28876"/>
      <state state_ref="oval:org.mitre.oval:ste:31201"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114323" version="1" comment="libxml2-python is earlier than 0:2.7.6-14.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:31201"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113930" version="1" comment="libxml2-devel is earlier than 0:2.7.6-14.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:31201"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113365" version="1" comment="xalan-j2-demo is earlier than 0:2.7.0-9.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38504"/>
      <state state_ref="oval:org.mitre.oval:ste:29871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113337" version="1" comment="xalan-j2-javadoc is earlier than 0:2.7.0-9.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38692"/>
      <state state_ref="oval:org.mitre.oval:ste:29871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113295" version="1" comment="xalan-j2-xsltc is earlier than 0:2.7.0-9.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38423"/>
      <state state_ref="oval:org.mitre.oval:ste:29871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113217" version="1" comment="xalan-j2-manual is earlier than 0:2.7.0-9.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38224"/>
      <state state_ref="oval:org.mitre.oval:ste:29871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113186" version="1" comment="xalan-j2 is earlier than 0:2.7.0-6jpp.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38637"/>
      <state state_ref="oval:org.mitre.oval:ste:30300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113048" version="1" comment="xalan-j2 is earlier than 0:2.7.0-9.9.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38637"/>
      <state state_ref="oval:org.mitre.oval:ste:29871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112942" version="1" comment="xalan-j2-javadoc is earlier than 0:2.7.0-6jpp.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38692"/>
      <state state_ref="oval:org.mitre.oval:ste:30300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112937" version="1" comment="xalan-j2-demo is earlier than 0:2.7.0-6jpp.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38504"/>
      <state state_ref="oval:org.mitre.oval:ste:30300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112887" version="1" comment="xalan-j2-manual is earlier than 0:2.7.0-6jpp.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38224"/>
      <state state_ref="oval:org.mitre.oval:ste:30300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112612" version="1" comment="xalan-j2-xsltc is earlier than 0:2.7.0-6jpp.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38423"/>
      <state state_ref="oval:org.mitre.oval:ste:30300"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113174" version="1" comment="389-ds-base is earlier than 0:1.2.11.15-32.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:36751"/>
      <state state_ref="oval:org.mitre.oval:ste:30381"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112812" version="1" comment="389-ds-base-libs is earlier than 0:1.2.11.15-32.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28949"/>
      <state state_ref="oval:org.mitre.oval:ste:30381"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112267" version="1" comment="389-ds-base-devel is earlier than 0:1.2.11.15-32.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29162"/>
      <state state_ref="oval:org.mitre.oval:ste:30381"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113222" version="1" comment="mutt is earlier than 5:1.5.20-4.20091214hg736b6a.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14378"/>
      <state state_ref="oval:org.mitre.oval:ste:30649"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113799" version="1" comment="samba4 is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37753"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113776" version="1" comment="samba4-devel is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29269"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113764" version="1" comment="samba4-dc is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28292"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113658" version="1" comment="samba4-libs is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28992"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113542" version="1" comment="samba4-winbind is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37434"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113527" version="1" comment="samba4-winbind-clients is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37536"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113457" version="1" comment="samba4-common is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29227"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113385" version="1" comment="samba4-client is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28823"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113311" version="1" comment="samba4-dc-libs is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28905"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113308" version="1" comment="samba4-pidl is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28846"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113223" version="1" comment="samba4-winbind-krb5-locator is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29221"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113088" version="1" comment="samba4-python is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29198"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113001" version="1" comment="samba4-swat is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29252"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112905" version="1" comment="samba4-test is earlier than 0:4.0.0-61.el6_5.rc4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28805"/>
      <state state_ref="oval:org.mitre.oval:ste:30598"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113902" version="1" comment="firefox is earlier than 0:24.4.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30281"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113576" version="1" comment="firefox is earlier than 0:24.4.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31105"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113033" version="1" comment="firefox is earlier than 0:24.4.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112878" version="1" comment="firefox is earlier than 0:24.4.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30660"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115398" version="1" comment="Red Hat Enterprise 7 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28686"/>
      <state state_ref="oval:org.mitre.oval:ste:31757"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115342" version="1" comment="Oracle Linux 7.x is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:23691"/>
      <state state_ref="oval:org.mitre.oval:ste:31675"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115369" version="1" comment="CentOS Linux 7.x is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:24078"/>
      <state state_ref="oval:org.mitre.oval:ste:31728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:116069" version="1" comment="firefox is earlier than 0:24.6.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31985"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115672" version="1" comment="xulrunner is earlier than 0:24.6.0-1.el7.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:31985"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115498" version="1" comment="firefox is earlier than 0:24.6.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31614"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115439" version="1" comment="xulrunner is earlier than 0:24.6.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:31614"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115278" version="1" comment="firefox is earlier than 0:24.6.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115251" version="1" comment="firefox is earlier than 0:24.6.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:31822"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:115120" version="1" comment="xulrunner-devel is earlier than 0:24.6.0-1.el7_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:31614"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114950" version="1" comment="firefox is earlier than 0:24.6.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30851"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114602" version="1" comment="firefox is earlier than 0:24.6.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:30859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113361" version="1" comment="samba-client is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113304" version="1" comment="samba3x-client is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14854"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113289" version="1" comment="samba-winbind-devel is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29445"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113272" version="1" comment="samba3x-common is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14673"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113240" version="1" comment="libsmbclient is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37433"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113193" version="1" comment="samba3x is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15124"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113155" version="1" comment="samba3x-swat is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15202"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113128" version="1" comment="samba3x-domainjoin-gui is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15045"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113084" version="1" comment="samba3x-winbind-devel is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15239"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113058" version="1" comment="samba is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113037" version="1" comment="samba-winbind-krb5-locator is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28660"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112992" version="1" comment="samba3x-winbind is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15095"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112784" version="1" comment="samba-domainjoin-gui is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112759" version="1" comment="samba-common is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38329"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112720" version="1" comment="samba-winbind-clients is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38277"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112639" version="1" comment="samba-swat is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112514" version="1" comment="samba3x-doc is earlier than 0:3.6.6-0.139.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14991"/>
      <state state_ref="oval:org.mitre.oval:ste:30779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112481" version="1" comment="samba-doc is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37787"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112379" version="1" comment="libsmbclient-devel is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112354" version="1" comment="samba-winbind is earlier than 0:3.6.9-168.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29389"/>
      <state state_ref="oval:org.mitre.oval:ste:30671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113341" version="1" comment="kernel-firmware is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113324" version="1" comment="kernel-headers is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38456"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113314" version="1" comment="kernel-devel is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113310" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113302" version="1" comment="kernel-debug is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113281" version="1" comment="perf is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113194" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113176" version="1" comment="python-perf is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113122" version="1" comment="kernel-doc is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113107" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38382"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113045" version="1" comment="kernel is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112903" version="1" comment="kernel-kdump is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37985"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112796" version="1" comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.11.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38242"/>
      <state state_ref="oval:org.mitre.oval:ste:30483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140799" version="1" comment="flash-plugin is earlier than 0:11.2.202.341-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:39142"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112925" version="1" comment="flash-plugin is earlier than 0:11.2.202.341-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:30194"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112948" version="1" comment="openswan is earlier than 0:2.6.32-27.2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14994"/>
      <state state_ref="oval:org.mitre.oval:ste:29817"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112726" version="1" comment="openswan-doc is earlier than 0:2.6.32-27.2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15278"/>
      <state state_ref="oval:org.mitre.oval:ste:29817"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112679" version="1" comment="openswan-doc is earlier than 0:2.6.32-7.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15278"/>
      <state state_ref="oval:org.mitre.oval:ste:30647"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112172" version="1" comment="openswan is earlier than 0:2.6.32-7.3.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14994"/>
      <state state_ref="oval:org.mitre.oval:ste:30647"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112980" version="1" comment="libtiff-devel is earlier than 0:3.9.4-10.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:30479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112957" version="1" comment="libtiff-static is earlier than 0:3.9.4-10.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30004"/>
      <state state_ref="oval:org.mitre.oval:ste:30479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112900" version="1" comment="libtiff is earlier than 0:3.9.4-10.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:30479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112960" version="1" comment="postgresql-contrib is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112943" version="1" comment="postgresql84-plpython is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15356"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112909" version="1" comment="postgresql84-contrib is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15329"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112907" version="1" comment="postgresql-pltcl is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29636"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112856" version="1" comment="postgresql-devel is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112809" version="1" comment="postgresql is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112803" version="1" comment="postgresql84-python is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15270"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112800" version="1" comment="postgresql84-test is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15176"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112782" version="1" comment="postgresql84-server is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15020"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112749" version="1" comment="postgresql-test is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112744" version="1" comment="postgresql-docs is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112717" version="1" comment="postgresql-libs is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112714" version="1" comment="postgresql84-tcl is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14440"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112698" version="1" comment="postgresql84-devel is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15349"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112684" version="1" comment="postgresql84-docs is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15371"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112658" version="1" comment="postgresql84-libs is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15091"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112596" version="1" comment="postgresql84-plperl is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14866"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112591" version="1" comment="postgresql-server is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112494" version="1" comment="postgresql-plperl is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29499"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112462" version="1" comment="postgresql-plpython is earlier than 0:8.4.20-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29607"/>
      <state state_ref="oval:org.mitre.oval:ste:30646"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112347" version="1" comment="postgresql84-pltcl is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15092"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112076" version="1" comment="postgresql84 is earlier than 0:8.4.20-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15160"/>
      <state state_ref="oval:org.mitre.oval:ste:30698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114025" version="1" comment="qemu-img is earlier than 2:0.12.1.2-2.415.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37800"/>
      <state state_ref="oval:org.mitre.oval:ste:30820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113998" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.415.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37253"/>
      <state state_ref="oval:org.mitre.oval:ste:30820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113919" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.415.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:30820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113840" version="1" comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.415.el6_5.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28988"/>
      <state state_ref="oval:org.mitre.oval:ste:30820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114253" version="1" comment="virt-viewer is earlier than 0:0.5.6-8.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38915"/>
      <state state_ref="oval:org.mitre.oval:ste:31533"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113413" version="1" comment="httpd-tools is earlier than 0:2.2.15-30.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29273"/>
      <state state_ref="oval:org.mitre.oval:ste:30389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113373" version="1" comment="httpd-devel is earlier than 0:2.2.15-30.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:30318"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113330" version="1" comment="httpd-devel is earlier than 0:2.2.15-30.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37757"/>
      <state state_ref="oval:org.mitre.oval:ste:30389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113327" version="1" comment="mod_ssl is earlier than 1:2.2.15-30.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:30007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113305" version="1" comment="httpd-manual is earlier than 0:2.2.15-30.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:30318"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113273" version="1" comment="httpd-manual is earlier than 0:2.2.15-30.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:30389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113096" version="1" comment="httpd is earlier than 0:2.2.15-30.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:30318"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113079" version="1" comment="httpd is earlier than 0:2.2.15-30.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:30389"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112757" version="1" comment="httpd-tools is earlier than 0:2.2.15-30.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29273"/>
      <state state_ref="oval:org.mitre.oval:ste:30318"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112517" version="1" comment="mod_ssl is earlier than 1:2.2.15-30.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:30732"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113282" version="1" comment="net-snmp is earlier than 1:5.5-49.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14390"/>
      <state state_ref="oval:org.mitre.oval:ste:29868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113264" version="1" comment="net-snmp-devel is earlier than 1:5.5-49.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14339"/>
      <state state_ref="oval:org.mitre.oval:ste:29868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113178" version="1" comment="net-snmp-utils is earlier than 1:5.5-49.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14287"/>
      <state state_ref="oval:org.mitre.oval:ste:29868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113165" version="1" comment="net-snmp-perl is earlier than 1:5.5-49.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14516"/>
      <state state_ref="oval:org.mitre.oval:ste:29868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113136" version="1" comment="net-snmp-libs is earlier than 1:5.5-49.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:36003"/>
      <state state_ref="oval:org.mitre.oval:ste:29868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112417" version="1" comment="net-snmp-python is earlier than 1:5.5-49.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29748"/>
      <state state_ref="oval:org.mitre.oval:ste:29868"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114639" version="1" comment="openssl097a is earlier than 0:0.9.7a-12.el5_10.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14181"/>
      <state state_ref="oval:org.mitre.oval:ste:31369"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114586" version="1" comment="openssl098e is earlier than 0:0.9.8e-18.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29469"/>
      <state state_ref="oval:org.mitre.oval:ste:31552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113166" version="1" comment="wireshark-devel is earlier than 0:1.8.10-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30148"/>
      <state state_ref="oval:org.mitre.oval:ste:30679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113051" version="1" comment="wireshark-gnome is earlier than 0:1.8.10-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35757"/>
      <state state_ref="oval:org.mitre.oval:ste:30679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112693" version="1" comment="wireshark is earlier than 0:1.8.10-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:30679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113173" version="1" comment="udisks is earlier than 0:1.0.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38727"/>
      <state state_ref="oval:org.mitre.oval:ste:30640"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113118" version="1" comment="udisks-devel-docs is earlier than 0:1.0.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38076"/>
      <state state_ref="oval:org.mitre.oval:ste:30640"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113071" version="1" comment="udisks-devel is earlier than 0:1.0.1-7.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38306"/>
      <state state_ref="oval:org.mitre.oval:ste:30640"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113786" version="1" comment="thunderbird is earlier than 0:24.4.0-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:31105"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113625" version="1" comment="thunderbird is earlier than 0:24.4.0-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30281"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112930" version="1" comment="thunderbird is earlier than 0:24.4.0-1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30660"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112746" version="1" comment="thunderbird is earlier than 0:24.4.0-1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:30610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140987" version="1" comment="flash-plugin is earlier than 0:11.2.202.346-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:39305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112587" version="1" comment="flash-plugin is earlier than 0:11.2.202.346-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37132"/>
      <state state_ref="oval:org.mitre.oval:ste:30149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114830" version="1" comment="libtasn1-tools is earlier than 0:2.3-6.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29423"/>
      <state state_ref="oval:org.mitre.oval:ste:31535"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114822" version="1" comment="libtasn1 is earlier than 0:2.3-6.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:36141"/>
      <state state_ref="oval:org.mitre.oval:ste:31535"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114745" version="1" comment="libtasn1-devel is earlier than 0:2.3-6.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29369"/>
      <state state_ref="oval:org.mitre.oval:ste:31535"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114375" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114263" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38317"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114196" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114182" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114180" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114142" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114105" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114099" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:114034" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113910" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.7.0-1jpp.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:38317"/>
      <state state_ref="oval:org.mitre.oval:ste:31008"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113637" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113583" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.7.0-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:31085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112982" version="1" comment="gnutls is earlier than 0:2.8.5-13.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14386"/>
      <state state_ref="oval:org.mitre.oval:ste:30714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112972" version="1" comment="gnutls-devel is earlier than 0:2.8.5-13.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14558"/>
      <state state_ref="oval:org.mitre.oval:ste:30714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112875" version="1" comment="gnutls-guile is earlier than 0:2.8.5-13.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28427"/>
      <state state_ref="oval:org.mitre.oval:ste:30714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:112709" version="1" comment="gnutls-utils is earlier than 0:2.8.5-13.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15003"/>
      <state state_ref="oval:org.mitre.oval:ste:30714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100423" version="1" comment="piranha is earlier than 0:0.8.6-4.el6_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29456"/>
      <state state_ref="oval:org.mitre.oval:ste:28000"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99593" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141224" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141145" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141122" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141029" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141020" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140996" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140766" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140232" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:39378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100491" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100435" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100434" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100378" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100365" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100224" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.15.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:27990"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113808" version="1" comment="kmod-kvm is earlier than 0:83-266.el5.centos.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:35146"/>
      <state state_ref="oval:org.mitre.oval:ste:30590"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113557" version="1" comment="libvirt is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15209"/>
      <state state_ref="oval:org.mitre.oval:ste:30795"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100475" version="1" comment="librsvg2-devel is earlier than 0:2.26.0-6.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30289"/>
      <state state_ref="oval:org.mitre.oval:ste:28122"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100428" version="1" comment="librsvg2 is earlier than 0:2.26.0-6.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30090"/>
      <state state_ref="oval:org.mitre.oval:ste:28122"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113809" version="1" comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29031"/>
      <state state_ref="oval:org.mitre.oval:ste:30795"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113156" version="1" comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15191"/>
      <state state_ref="oval:org.mitre.oval:ste:30795"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100310" version="1" comment="firefox is earlier than 0:24.3.0-2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27701"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100086" version="1" comment="firefox is earlier than 0:24.3.0-2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27371"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99960" version="1" comment="openldap is earlier than 0:2.4.23-34.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14650"/>
      <state state_ref="oval:org.mitre.oval:ste:27799"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100420" version="1" comment="openldap-servers-sql is earlier than 0:2.4.23-34.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14387"/>
      <state state_ref="oval:org.mitre.oval:ste:27799"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100410" version="1" comment="openldap-servers is earlier than 0:2.4.23-34.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14676"/>
      <state state_ref="oval:org.mitre.oval:ste:27799"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100214" version="1" comment="openldap-clients is earlier than 0:2.4.23-34.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13745"/>
      <state state_ref="oval:org.mitre.oval:ste:27799"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100185" version="1" comment="openldap-devel is earlier than 0:2.4.23-34.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14680"/>
      <state state_ref="oval:org.mitre.oval:ste:27799"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100489" version="1" comment="libvirt-client is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29031"/>
      <state state_ref="oval:org.mitre.oval:ste:27954"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100480" version="1" comment="libvirt-python is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15191"/>
      <state state_ref="oval:org.mitre.oval:ste:27954"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100357" version="1" comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28971"/>
      <state state_ref="oval:org.mitre.oval:ste:27954"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100281" version="1" comment="libvirt is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15209"/>
      <state state_ref="oval:org.mitre.oval:ste:27954"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100223" version="1" comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14880"/>
      <state state_ref="oval:org.mitre.oval:ste:27954"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140999" version="1" comment="flash-plugin is earlier than 0:11.2.202.335-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:38649"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100327" version="1" comment="flash-plugin is earlier than 0:11.2.202.335-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:28013"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100195" version="1" comment="wget is earlier than 0:1.12-1.11.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14591"/>
      <state state_ref="oval:org.mitre.oval:ste:27916"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99954" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.51-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:27670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99867" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.51-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:27670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100317" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.51-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:27670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100297" version="1" comment="java-1.7.0-oracle-javafx is earlier than 1:1.7.0.51-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29158"/>
      <state state_ref="oval:org.mitre.oval:ste:27670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100244" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.51-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28813"/>
      <state state_ref="oval:org.mitre.oval:ste:27670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100240" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.51-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28501"/>
      <state state_ref="oval:org.mitre.oval:ste:27670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99514" version="1" comment="flash-plugin is earlier than 0:11.2.202.336-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27714"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141146" version="1" comment="flash-plugin is earlier than 0:11.2.202.336-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:39199"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99905" version="1" comment="bzip2 is earlier than 0:1.0.5-7.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14678"/>
      <state state_ref="oval:org.mitre.oval:ste:27708"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99897" version="1" comment="bzip2-libs is earlier than 0:1.0.5-7.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14666"/>
      <state state_ref="oval:org.mitre.oval:ste:27708"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99760" version="1" comment="bzip2-devel is earlier than 0:1.0.5-7.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14253"/>
      <state state_ref="oval:org.mitre.oval:ste:27708"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99963" version="1" comment="apr-util-ldap is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29939"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99933" version="1" comment="apr-util is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14992"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99866" version="1" comment="apr-util-docs is earlier than 0:1.2.7-11.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15199"/>
      <state state_ref="oval:org.mitre.oval:ste:27750"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99848" version="1" comment="apr-util-mysql is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29834"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99823" version="1" comment="apr-util-mysql is earlier than 0:1.2.7-11.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29834"/>
      <state state_ref="oval:org.mitre.oval:ste:27750"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99298" version="1" comment="apr-util-devel is earlier than 0:1.2.7-11.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15236"/>
      <state state_ref="oval:org.mitre.oval:ste:27750"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99237" version="1" comment="apr-util-pgsql is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30282"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100112" version="1" comment="apr-util-odbc is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30351"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100104" version="1" comment="apr-util-sqlite is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30161"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100092" version="1" comment="apr-util-devel is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15236"/>
      <state state_ref="oval:org.mitre.oval:ste:27599"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100054" version="1" comment="apr-util is earlier than 0:1.2.7-11.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14992"/>
      <state state_ref="oval:org.mitre.oval:ste:27750"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99992" version="1" comment="openssl-static is earlier than 0:1.0.0-4.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:27785"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99915" version="1" comment="openssl is earlier than 0:1.0.0-4.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:27785"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99699" version="1" comment="openssl-devel is earlier than 0:1.0.0-4.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:27785"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99022" version="1" comment="openssl-perl is earlier than 0:1.0.0-4.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:27785"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99976" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.2-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:27823"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99871" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.2-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:27823"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99606" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.2-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:27823"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99523" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.2-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:27823"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99373" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.2-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:27823"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99003" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.2-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:27823"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98977" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.2-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:27823"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99889" version="1" comment="glibc-common is earlier than 0:2.12-1.7.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:27651"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99888" version="1" comment="glibc-static is earlier than 0:2.12-1.7.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30224"/>
      <state state_ref="oval:org.mitre.oval:ste:27651"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99766" version="1" comment="glibc-utils is earlier than 0:2.12-1.7.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:27651"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99757" version="1" comment="glibc is earlier than 0:2.12-1.7.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:27651"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99672" version="1" comment="glibc-headers is earlier than 0:2.12-1.7.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:27651"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99543" version="1" comment="glibc-devel is earlier than 0:2.12-1.7.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:27651"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99369" version="1" comment="nscd is earlier than 0:2.12-1.7.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:27651"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99996" version="1" comment="finch-devel is earlier than 0:2.6.6-6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:27840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99993" version="1" comment="pidgin-devel is earlier than 0:2.6.6-6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:27840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99890" version="1" comment="pidgin-perl is earlier than 0:2.6.6-6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:27840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99826" version="1" comment="libpurple-devel is earlier than 0:2.6.6-6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:27840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99814" version="1" comment="pidgin-docs is earlier than 0:2.6.6-6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14724"/>
      <state state_ref="oval:org.mitre.oval:ste:27840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99702" version="1" comment="pidgin is earlier than 0:2.6.6-6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:27840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99581" version="1" comment="libpurple-perl is earlier than 0:2.6.6-6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:27840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99574" version="1" comment="libpurple-tcl is earlier than 0:2.6.6-6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:27840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99378" version="1" comment="finch is earlier than 0:2.6.6-6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:27840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100010" version="1" comment="libpurple is earlier than 0:2.6.6-6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:27840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99904" version="1" comment="poppler-utils is earlier than 0:0.12.4-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14640"/>
      <state state_ref="oval:org.mitre.oval:ste:27847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99870" version="1" comment="poppler is earlier than 0:0.12.4-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14394"/>
      <state state_ref="oval:org.mitre.oval:ste:27847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99829" version="1" comment="poppler-glib is earlier than 0:0.12.4-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30194"/>
      <state state_ref="oval:org.mitre.oval:ste:27847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99774" version="1" comment="poppler-qt is earlier than 0:0.12.4-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29865"/>
      <state state_ref="oval:org.mitre.oval:ste:27847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99756" version="1" comment="poppler-devel is earlier than 0:0.12.4-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14966"/>
      <state state_ref="oval:org.mitre.oval:ste:27847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99747" version="1" comment="poppler-glib-devel is earlier than 0:0.12.4-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30069"/>
      <state state_ref="oval:org.mitre.oval:ste:27847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99651" version="1" comment="poppler-qt4-devel is earlier than 0:0.12.4-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30343"/>
      <state state_ref="oval:org.mitre.oval:ste:27847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99650" version="1" comment="poppler-qt-devel is earlier than 0:0.12.4-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30296"/>
      <state state_ref="oval:org.mitre.oval:ste:27847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99456" version="1" comment="poppler-qt4 is earlier than 0:0.12.4-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29373"/>
      <state state_ref="oval:org.mitre.oval:ste:27847"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99988" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99977" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99913" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99841" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99840" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99711" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99645" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99638" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99549" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99487" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100131" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.0-1jpp.4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:27402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100048" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100039" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100029" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100028" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.0-1jpp.3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:27863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100110" version="1" comment="thunderbird is earlier than 0:3.1.7-3.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27607"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99949" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141081" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29107"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141057" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141052" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141036" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140896" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140881" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.1-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:39547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100483" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100425" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100370" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29107"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100295" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100082" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.6.1-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:27888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99943" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99779" version="1" comment="kernel-headers is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99656" version="1" comment="kernel-doc is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100521" version="1" comment="kernel-abi-whitelists is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29639"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100510" version="1" comment="python-perf is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100482" version="1" comment="kernel-firmware is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100473" version="1" comment="kernel-debug is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100383" version="1" comment="kernel is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100307" version="1" comment="kernel-devel is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100286" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100263" version="1" comment="kernel-kdump is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100084" version="1" comment="perf is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100076" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-431.5.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:28066"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100157" version="1" comment="libvpx-utils is earlier than 0:0.9.0-8.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30370"/>
      <state state_ref="oval:org.mitre.oval:ste:27619"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100138" version="1" comment="libvpx is earlier than 0:0.9.0-8.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30327"/>
      <state state_ref="oval:org.mitre.oval:ste:27619"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100071" version="1" comment="libvpx-devel is earlier than 0:0.9.0-8.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30314"/>
      <state state_ref="oval:org.mitre.oval:ste:27619"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99909" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.31.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:27834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99882" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.31.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:27834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99547" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.31.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:27834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99536" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.31.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:27834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99418" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.31.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:27834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99941" version="1" comment="freetype-devel is earlier than 0:2.3.11-6.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:27009"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99899" version="1" comment="freetype-demos is earlier than 0:2.3.11-6.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:27009"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99767" version="1" comment="freetype is earlier than 0:2.2.1-28.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:27485"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99759" version="1" comment="freetype-demos is earlier than 0:2.2.1-28.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:27485"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99736" version="1" comment="freetype is earlier than 0:2.3.11-6.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:27009"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100020" version="1" comment="freetype-devel is earlier than 0:2.2.1-28.el5_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:27485"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99886" version="1" comment="samba-swat is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99856" version="1" comment="samba-winbind-devel is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29445"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99834" version="1" comment="samba-client is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99815" version="1" comment="samba-domainjoin-gui is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99808" version="1" comment="samba-common is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14032"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99746" version="1" comment="libsmbclient-devel is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99659" version="1" comment="libsmbclient is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15389"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99602" version="1" comment="samba-doc is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29416"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99545" version="1" comment="samba is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99431" version="1" comment="samba-winbind is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29389"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99282" version="1" comment="samba-winbind-clients is earlier than 0:3.5.4-68.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29486"/>
      <state state_ref="oval:org.mitre.oval:ste:27820"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99900" version="1" comment="firefox is earlier than 0:3.6.12-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27702"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99511" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.12-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27576"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99488" version="1" comment="xulrunner is earlier than 0:1.9.2.12-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27576"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99807" version="1" comment="krb5 is earlier than 0:1.8.2-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14120"/>
      <state state_ref="oval:org.mitre.oval:ste:26867"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99806" version="1" comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29392"/>
      <state state_ref="oval:org.mitre.oval:ste:26867"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99752" version="1" comment="krb5-server is earlier than 0:1.8.2-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:26867"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99560" version="1" comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:26867"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99496" version="1" comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:26867"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99275" version="1" comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:26867"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99039" version="1" comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29451"/>
      <state state_ref="oval:org.mitre.oval:ste:26867"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99982" version="1" comment="acroread-plugin is earlier than 0:9.4.1-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:27658"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99895" version="1" comment="acroread is earlier than 0:9.4.1-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:27658"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99687" version="1" comment="acroread is earlier than 0:9.4.1-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:26871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100085" version="1" comment="acroread-plugin is earlier than 0:9.4.1-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:26871"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99869" version="1" comment="freetype-devel is earlier than 0:2.3.11-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:27479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99842" version="1" comment="freetype is earlier than 0:2.3.11-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:27479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98946" version="1" comment="freetype-demos is earlier than 0:2.3.11-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:27479"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99999" version="1" comment="bind-sdb is earlier than 32:9.7.0-5.P2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:27320"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99995" version="1" comment="bind is earlier than 32:9.7.0-5.P2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:27320"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99925" version="1" comment="bind-devel is earlier than 32:9.7.0-5.P2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:27320"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99625" version="1" comment="bind-chroot is earlier than 32:9.7.0-5.P2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:27320"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99584" version="1" comment="bind-utils is earlier than 32:9.7.0-5.P2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:27320"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99538" version="1" comment="bind-libs is earlier than 32:9.7.0-5.P2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:27320"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99946" version="1" comment="emacs-git is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29238"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99938" version="1" comment="gitweb is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28842"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99883" version="1" comment="gitk is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4940"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99843" version="1" comment="git-all is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28590"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99768" version="1" comment="git-email is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4906"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99724" version="1" comment="git-svn is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4880"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99181" version="1" comment="git-daemon is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29408"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100161" version="1" comment="git is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29380"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100087" version="1" comment="emacs-git-el is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29215"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100070" version="1" comment="git-cvs is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4210"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100068" version="1" comment="git-gui is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29393"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100053" version="1" comment="perl-Git is earlier than 0:1.7.1-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29255"/>
      <state state_ref="oval:org.mitre.oval:ste:27551"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99907" version="1" comment="cups-devel is earlier than 1:1.4.2-35.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14076"/>
      <state state_ref="oval:org.mitre.oval:ste:27514"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99819" version="1" comment="cups-lpd is earlier than 1:1.4.2-35.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14688"/>
      <state state_ref="oval:org.mitre.oval:ste:27514"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99816" version="1" comment="cups is earlier than 1:1.4.2-35.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14199"/>
      <state state_ref="oval:org.mitre.oval:ste:27514"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99684" version="1" comment="cups-libs is earlier than 1:1.4.2-35.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14195"/>
      <state state_ref="oval:org.mitre.oval:ste:27514"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99505" version="1" comment="cups-php is earlier than 1:1.4.2-35.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29023"/>
      <state state_ref="oval:org.mitre.oval:ste:27514"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99966" version="1" comment="finch-devel is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99911" version="1" comment="pidgin is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99785" version="1" comment="libpurple-perl is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100512" version="1" comment="libpurple-devel is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100505" version="1" comment="pidgin-devel is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100487" version="1" comment="pidgin is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100448" version="1" comment="libpurple-devel is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100426" version="1" comment="finch is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100413" version="1" comment="libpurple-perl is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100391" version="1" comment="pidgin-perl is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100321" version="1" comment="pidgin-perl is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100258" version="1" comment="pidgin-devel is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100252" version="1" comment="pidgin-docs is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14724"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100193" version="1" comment="libpurple is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100189" version="1" comment="libpurple-tcl is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100181" version="1" comment="finch-devel is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100119" version="1" comment="libpurple is earlier than 0:2.7.9-27.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:28059"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100061" version="1" comment="finch is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100046" version="1" comment="libpurple-tcl is earlier than 0:2.6.6-32.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:28043"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98522" version="1" comment="firefox is earlier than 0:3.6.22-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27194"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98450" version="1" comment="xulrunner is earlier than 0:1.9.2.22-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26927"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98413" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26708"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98348" version="1" comment="firefox is earlier than 0:3.6.22-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26824"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98144" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.22-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26927"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98050" version="1" comment="xulrunner is earlier than 0:1.9.2.22-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26708"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98592" version="1" comment="firefox is earlier than 0:3.6.23-2.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26667"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98580" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27010"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98441" version="1" comment="xulrunner is earlier than 0:1.9.2.23-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27133"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98437" version="1" comment="xulrunner is earlier than 0:1.9.2.23-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27010"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98338" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.23-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27133"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98221" version="1" comment="firefox is earlier than 0:3.6.23-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27460"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99953" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:27979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99903" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:27979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99792" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:27979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99398" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-3.1.13.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:27775"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100373" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:27979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100331" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-3.1.13.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:27775"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100267" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:27775"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100233" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-3.1.13.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:27979"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100218" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-3.1.13.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:27775"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100042" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-3.1.13.1.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:27775"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99967" version="1" comment="pam is earlier than 0:1.1.1-4.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14730"/>
      <state state_ref="oval:org.mitre.oval:ste:27727"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99964" version="1" comment="pam-devel is earlier than 0:1.1.1-4.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14734"/>
      <state state_ref="oval:org.mitre.oval:ste:27727"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98886" version="1" comment="krb5-devel is earlier than 0:1.9-22.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:27611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98784" version="1" comment="krb5-libs is earlier than 0:1.9-22.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:27611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98783" version="1" comment="krb5-workstation is earlier than 0:1.9-22.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:27611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98669" version="1" comment="krb5-pkinit-openssl is earlier than 0:1.9-22.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29392"/>
      <state state_ref="oval:org.mitre.oval:ste:27611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98629" version="1" comment="krb5-server-ldap is earlier than 0:1.9-22.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29451"/>
      <state state_ref="oval:org.mitre.oval:ste:27611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98360" version="1" comment="krb5-server is earlier than 0:1.9-22.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:27611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98208" version="1" comment="krb5 is earlier than 0:1.9-22.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14120"/>
      <state state_ref="oval:org.mitre.oval:ste:27611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98826" version="1" comment="ipmitool is earlier than 0:1.8.11-12.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29978"/>
      <state state_ref="oval:org.mitre.oval:ste:27521"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99932" version="1" comment="cvs is earlier than 0:1.11.23-11.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:933"/>
      <state state_ref="oval:org.mitre.oval:ste:27730"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99054" version="1" comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-35.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29298"/>
      <state state_ref="oval:org.mitre.oval:ste:27338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99048" version="1" comment="tomcat6-webapps is earlier than 0:6.0.24-35.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29371"/>
      <state state_ref="oval:org.mitre.oval:ste:27338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99016" version="1" comment="tomcat6-admin-webapps is earlier than 0:6.0.24-35.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28477"/>
      <state state_ref="oval:org.mitre.oval:ste:27338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99014" version="1" comment="tomcat6-lib is earlier than 0:6.0.24-35.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29391"/>
      <state state_ref="oval:org.mitre.oval:ste:27338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98941" version="1" comment="tomcat6-javadoc is earlier than 0:6.0.24-35.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28454"/>
      <state state_ref="oval:org.mitre.oval:ste:27338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98884" version="1" comment="tomcat6-lib is earlier than 0:6.0.24-35.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29391"/>
      <state state_ref="oval:org.mitre.oval:ste:27161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98854" version="1" comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-35.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29264"/>
      <state state_ref="oval:org.mitre.oval:ste:27161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98853" version="1" comment="tomcat6-javadoc is earlier than 0:6.0.24-35.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28454"/>
      <state state_ref="oval:org.mitre.oval:ste:27161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98838" version="1" comment="tomcat6-webapps is earlier than 0:6.0.24-35.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29371"/>
      <state state_ref="oval:org.mitre.oval:ste:27161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98734" version="1" comment="tomcat6 is earlier than 0:6.0.24-35.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29276"/>
      <state state_ref="oval:org.mitre.oval:ste:27338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98617" version="1" comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-35.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29298"/>
      <state state_ref="oval:org.mitre.oval:ste:27161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98608" version="1" comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-35.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29382"/>
      <state state_ref="oval:org.mitre.oval:ste:27338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98590" version="1" comment="tomcat6-admin-webapps is earlier than 0:6.0.24-35.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28477"/>
      <state state_ref="oval:org.mitre.oval:ste:27161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98568" version="1" comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-35.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29382"/>
      <state state_ref="oval:org.mitre.oval:ste:27161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98519" version="1" comment="tomcat6-docs-webapp is earlier than 0:6.0.24-35.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29374"/>
      <state state_ref="oval:org.mitre.oval:ste:27161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98423" version="1" comment="tomcat6 is earlier than 0:6.0.24-35.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29276"/>
      <state state_ref="oval:org.mitre.oval:ste:27161"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98289" version="1" comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-35.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29264"/>
      <state state_ref="oval:org.mitre.oval:ste:27338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98194" version="1" comment="tomcat6-docs-webapp is earlier than 0:6.0.24-35.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29374"/>
      <state state_ref="oval:org.mitre.oval:ste:27338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98860" version="1" comment="libarchive-devel is earlier than 0:2.8.3-3.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30325"/>
      <state state_ref="oval:org.mitre.oval:ste:27207"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98300" version="1" comment="libarchive is earlier than 0:2.8.3-3.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30279"/>
      <state state_ref="oval:org.mitre.oval:ste:27207"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98898" version="1" comment="libicu is earlier than 0:4.2.1-9.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14735"/>
      <state state_ref="oval:org.mitre.oval:ste:27519"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98896" version="1" comment="libicu-devel is earlier than 0:3.6-5.16.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14587"/>
      <state state_ref="oval:org.mitre.oval:ste:27520"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98771" version="1" comment="libicu-devel is earlier than 0:4.2.1-9.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14587"/>
      <state state_ref="oval:org.mitre.oval:ste:27519"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98768" version="1" comment="icu is earlier than 0:3.6-5.16.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14949"/>
      <state state_ref="oval:org.mitre.oval:ste:27520"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98751" version="1" comment="libicu-doc is earlier than 0:4.2.1-9.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14890"/>
      <state state_ref="oval:org.mitre.oval:ste:27519"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98443" version="1" comment="libicu is earlier than 0:3.6-5.16.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14735"/>
      <state state_ref="oval:org.mitre.oval:ste:27520"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98424" version="1" comment="icu is earlier than 0:4.2.1-9.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14949"/>
      <state state_ref="oval:org.mitre.oval:ste:27519"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98133" version="1" comment="libicu-doc is earlier than 0:3.6-5.16.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14890"/>
      <state state_ref="oval:org.mitre.oval:ste:27520"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98773" version="1" comment="acroread-plugin is earlier than 0:9.4.6-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:27440"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98628" version="1" comment="acroread-plugin is earlier than 0:9.4.6-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:26779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98469" version="1" comment="acroread is earlier than 0:9.4.6-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:27440"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97774" version="1" comment="acroread is earlier than 0:9.4.6-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:26779"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98521" version="1" comment="qt-devel is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14278"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98486" version="1" comment="qt is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14421"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98460" version="1" comment="phonon-backend-gstreamer is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29039"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98435" version="1" comment="qt-postgresql is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29278"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98379" version="1" comment="qt-odbc is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29487"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98285" version="1" comment="qt-doc is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29270"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98266" version="1" comment="qt-sqlite is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29502"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98254" version="1" comment="qt-examples is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29248"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98183" version="1" comment="qt-mysql is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28542"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98107" version="1" comment="qt-demos is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29395"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97613" version="1" comment="qt-x11 is earlier than 1:4.6.2-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29346"/>
      <state state_ref="oval:org.mitre.oval:ste:26956"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98006" version="1" comment="thunderbird is earlier than 0:3.1.12-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26949"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98335" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:27480"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98329" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:27480"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98281" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:27114"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98207" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:27114"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98174" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:27480"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98158" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.5-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:27480"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98141" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:27114"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98115" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:27114"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98113" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.5-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:27480"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97848" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:27114"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97844" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:27114"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97695" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:27114"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97576" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.5-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:27480"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97523" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:27480"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97344" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.5-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:27114"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98659" version="1" comment="icedtea-web is earlier than 0:1.0.6-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29552"/>
      <state state_ref="oval:org.mitre.oval:ste:27171"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98620" version="1" comment="icedtea-web-javadoc is earlier than 0:1.0.6-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29549"/>
      <state state_ref="oval:org.mitre.oval:ste:27171"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98861" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:27632"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98775" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.0-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:27500"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98763" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:27632"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98754" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:27500"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98729" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:27500"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98668" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:27500"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98667" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.0-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:27632"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98657" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:27500"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98598" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.0-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:27632"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98475" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:27500"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98345" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.0-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:27632"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98324" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.0-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:27632"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98297" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.0-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:27500"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97910" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.0-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:27632"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97885" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.13.0-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:27500"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98698" version="1" comment="bind is earlier than 32:9.7.3-2.el6_1.P3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:26765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98690" version="1" comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:26765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98665" version="1" comment="bind-utils is earlier than 30:9.3.6-16.P1.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:27625"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98609" version="1" comment="caching-nameserver is earlier than 30:9.3.6-16.P1.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:27625"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98553" version="1" comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:26765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98532" version="1" comment="bind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:27625"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98439" version="1" comment="bind-libbind-devel is earlier than 30:9.3.6-16.P1.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:27625"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98426" version="1" comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:26765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98408" version="1" comment="bind-libs is earlier than 30:9.3.6-16.P1.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:27625"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98367" version="1" comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:26765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98202" version="1" comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:26765"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98197" version="1" comment="bind-chroot is earlier than 30:9.3.6-16.P1.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:27625"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98132" version="1" comment="bind-sdb is earlier than 30:9.3.6-16.P1.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:27625"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98079" version="1" comment="bind is earlier than 30:9.3.6-16.P1.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:27625"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98420" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26981"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98391" version="1" comment="xulrunner is earlier than 0:1.9.2.20-3.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98240" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.20-3.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27261"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97841" version="1" comment="xulrunner is earlier than 0:1.9.2.20-3.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26981"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98952" version="1" comment="krb5-appl-servers is earlier than 0:1.0.1-7.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30049"/>
      <state state_ref="oval:org.mitre.oval:ste:27151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98908" version="1" comment="krb5-appl-clients is earlier than 0:1.0.1-7.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29343"/>
      <state state_ref="oval:org.mitre.oval:ste:27151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98864" version="1" comment="krb5-appl is earlier than 0:1.0.1-7.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29288"/>
      <state state_ref="oval:org.mitre.oval:ste:27151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99710" version="1" comment="mod_auth_mysql is earlier than 1:3.0.0-11.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14493"/>
      <state state_ref="oval:org.mitre.oval:ste:27463"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98863" version="1" comment="dhcp-common is earlier than 12:4.1.1-25.P1.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29015"/>
      <state state_ref="oval:org.mitre.oval:ste:27421"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98804" version="1" comment="dhcp is earlier than 12:4.1.1-25.P1.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3459"/>
      <state state_ref="oval:org.mitre.oval:ste:27421"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98525" version="1" comment="dhcp-devel is earlier than 12:4.1.1-25.P1.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3630"/>
      <state state_ref="oval:org.mitre.oval:ste:27421"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98493" version="1" comment="dhclient is earlier than 12:4.1.1-25.P1.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15218"/>
      <state state_ref="oval:org.mitre.oval:ste:27421"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99518" version="1" comment="flash-plugin is earlier than 0:10.1.102.64-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27283"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99985" version="1" comment="openssl is earlier than 0:1.0.0-4.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:26873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99950" version="1" comment="openssl-static is earlier than 0:1.0.0-4.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:26873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99798" version="1" comment="openssl-perl is earlier than 0:1.0.0-4.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:26873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99143" version="1" comment="openssl-devel is earlier than 0:1.0.0-4.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:26873"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98336" version="1" comment="dbus is earlier than 0:1.1.2-16.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14213"/>
      <state state_ref="oval:org.mitre.oval:ste:27305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98328" version="1" comment="dbus-devel is earlier than 0:1.1.2-16.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14425"/>
      <state state_ref="oval:org.mitre.oval:ste:27305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98321" version="1" comment="dbus is earlier than 1:1.2.24-5.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14213"/>
      <state state_ref="oval:org.mitre.oval:ste:27475"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98270" version="1" comment="dbus-libs is earlier than 0:1.1.2-16.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15234"/>
      <state state_ref="oval:org.mitre.oval:ste:27305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98184" version="1" comment="dbus-x11 is earlier than 0:1.1.2-16.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14132"/>
      <state state_ref="oval:org.mitre.oval:ste:27305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98046" version="1" comment="dbus-x11 is earlier than 1:1.2.24-5.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14132"/>
      <state state_ref="oval:org.mitre.oval:ste:27475"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98037" version="1" comment="dbus-devel is earlier than 1:1.2.24-5.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14425"/>
      <state state_ref="oval:org.mitre.oval:ste:27475"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98018" version="1" comment="dbus-libs is earlier than 1:1.2.24-5.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15234"/>
      <state state_ref="oval:org.mitre.oval:ste:27475"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97803" version="1" comment="dbus-doc is earlier than 1:1.2.24-5.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30088"/>
      <state state_ref="oval:org.mitre.oval:ste:27475"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99973" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:27410"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141222" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:39465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141185" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:39465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141143" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:39465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141058" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:39465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:141017" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:39465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140911" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:39465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140793" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:39465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:140690" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.16.5-1jpp.1.el5_10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:39465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100452" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:27410"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100379" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:27410"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100372" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:27410"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100369" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:27410"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100347" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:27410"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100222" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.16.5-1jpp.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:27410"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98545" version="1" comment="qt-mysql is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28542"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98524" version="1" comment="qt-x11 is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29346"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98485" version="1" comment="qt is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14421"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98479" version="1" comment="phonon-backend-gstreamer is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29039"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98472" version="1" comment="qt-doc is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29270"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98471" version="1" comment="qt-sqlite is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29502"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98354" version="1" comment="qt-examples is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29248"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98147" version="1" comment="qt-postgresql is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29278"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98110" version="1" comment="qt-odbc is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29487"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98100" version="1" comment="qt-demos is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29395"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97678" version="1" comment="qt-devel is earlier than 1:4.6.2-17.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14278"/>
      <state state_ref="oval:org.mitre.oval:ste:27051"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98747" version="1" comment="perl-IO-Compress-Zlib is earlier than 0:2.020-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28533"/>
      <state state_ref="oval:org.mitre.oval:ste:27522"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98730" version="1" comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29541"/>
      <state state_ref="oval:org.mitre.oval:ste:27274"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98725" version="1" comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29307"/>
      <state state_ref="oval:org.mitre.oval:ste:27221"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98713" version="1" comment="perl-IPC-Cmd is earlier than 1:0.56-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29378"/>
      <state state_ref="oval:org.mitre.oval:ste:27553"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98704" version="1" comment="perl-Params-Check is earlier than 1:0.26-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28644"/>
      <state state_ref="oval:org.mitre.oval:ste:27297"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98701" version="1" comment="perl-Module-Load is earlier than 1:0.16-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29406"/>
      <state state_ref="oval:org.mitre.oval:ste:27642"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98691" version="1" comment="perl-Module-Build is earlier than 1:0.3500-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28605"/>
      <state state_ref="oval:org.mitre.oval:ste:27594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98688" version="1" comment="perl-CPANPLUS is earlier than 0:0.88-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29281"/>
      <state state_ref="oval:org.mitre.oval:ste:27540"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98683" version="1" comment="perl-Log-Message is earlier than 1:0.02-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29132"/>
      <state state_ref="oval:org.mitre.oval:ste:27596"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98682" version="1" comment="perl-libs is earlier than 4:5.10.1-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29045"/>
      <state state_ref="oval:org.mitre.oval:ste:27614"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98680" version="1" comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29399"/>
      <state state_ref="oval:org.mitre.oval:ste:27539"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98679" version="1" comment="perl-devel is earlier than 4:5.10.1-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29262"/>
      <state state_ref="oval:org.mitre.oval:ste:27614"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98677" version="1" comment="perl-ExtUtils-Embed is earlier than 0:1.28-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29397"/>
      <state state_ref="oval:org.mitre.oval:ste:27123"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98656" version="1" comment="perl-Module-Loaded is earlier than 1:0.02-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29291"/>
      <state state_ref="oval:org.mitre.oval:ste:27596"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98648" version="1" comment="perl-Compress-Zlib is earlier than 0:2.020-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29479"/>
      <state state_ref="oval:org.mitre.oval:ste:27522"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98624" version="1" comment="perl-core is earlier than 0:5.10.1-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29342"/>
      <state state_ref="oval:org.mitre.oval:ste:27578"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98601" version="1" comment="perl-Module-CoreList is earlier than 0:2.18-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29351"/>
      <state state_ref="oval:org.mitre.oval:ste:27466"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98597" version="1" comment="perl-version is earlier than 3:0.77-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29312"/>
      <state state_ref="oval:org.mitre.oval:ste:27374"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98523" version="1" comment="perl-Test-Harness is earlier than 0:3.17-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29175"/>
      <state state_ref="oval:org.mitre.oval:ste:27536"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98520" version="1" comment="perl-parent is earlier than 1:0.221-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29519"/>
      <state state_ref="oval:org.mitre.oval:ste:27422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98517" version="1" comment="perl-Package-Constants is earlier than 1:0.02-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29476"/>
      <state state_ref="oval:org.mitre.oval:ste:27596"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98514" version="1" comment="perl-Term-UI is earlier than 0:0.20-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29341"/>
      <state state_ref="oval:org.mitre.oval:ste:27330"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98507" version="1" comment="perl-Time-HiRes is earlier than 4:1.9721-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29458"/>
      <state state_ref="oval:org.mitre.oval:ste:27196"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98504" version="1" comment="perl is earlier than 4:5.10.1-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14460"/>
      <state state_ref="oval:org.mitre.oval:ste:27614"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98491" version="1" comment="perl-File-Fetch is earlier than 0:0.26-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29401"/>
      <state state_ref="oval:org.mitre.oval:ste:27279"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98427" version="1" comment="perl-Time-Piece is earlier than 0:1.15-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29412"/>
      <state state_ref="oval:org.mitre.oval:ste:27493"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98410" version="1" comment="perl-Log-Message-Simple is earlier than 0:0.04-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29521"/>
      <state state_ref="oval:org.mitre.oval:ste:26822"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98399" version="1" comment="perl-IO-Zlib is earlier than 1:1.09-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29321"/>
      <state state_ref="oval:org.mitre.oval:ste:26690"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98370" version="1" comment="perl-Archive-Tar is earlier than 0:1.58-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15210"/>
      <state state_ref="oval:org.mitre.oval:ste:27631"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98368" version="1" comment="perl-Pod-Escapes is earlier than 1:1.04-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29097"/>
      <state state_ref="oval:org.mitre.oval:ste:27547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98339" version="1" comment="perl-suidperl is earlier than 4:5.10.1-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13815"/>
      <state state_ref="oval:org.mitre.oval:ste:27614"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98302" version="1" comment="perl-Test-Simple is earlier than 0:0.92-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29437"/>
      <state state_ref="oval:org.mitre.oval:ste:27589"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98210" version="1" comment="perl-Pod-Simple is earlier than 1:3.13-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29403"/>
      <state state_ref="oval:org.mitre.oval:ste:27311"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98205" version="1" comment="perl-Module-Pluggable is earlier than 1:3.90-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29466"/>
      <state state_ref="oval:org.mitre.oval:ste:27573"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98204" version="1" comment="perl-CPAN is earlier than 0:1.9402-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14597"/>
      <state state_ref="oval:org.mitre.oval:ste:27309"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98196" version="1" comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29426"/>
      <state state_ref="oval:org.mitre.oval:ste:27571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98135" version="1" comment="perl-Archive-Extract is earlier than 1:0.38-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28800"/>
      <state state_ref="oval:org.mitre.oval:ste:27504"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98112" version="1" comment="perl-Module-Load-Conditional is earlier than 0:0.30-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29116"/>
      <state state_ref="oval:org.mitre.oval:ste:27569"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98093" version="1" comment="perl-CGI is earlier than 0:3.51-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14319"/>
      <state state_ref="oval:org.mitre.oval:ste:27356"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98081" version="1" comment="perl-IO-Compress-Base is earlier than 0:2.020-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29330"/>
      <state state_ref="oval:org.mitre.oval:ste:27522"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98023" version="1" comment="perl-Object-Accessor is earlier than 1:0.34-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29258"/>
      <state state_ref="oval:org.mitre.oval:ste:27541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97972" version="1" comment="perl-Digest-SHA is earlier than 1:5.47-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29179"/>
      <state state_ref="oval:org.mitre.oval:ste:27524"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97904" version="1" comment="perl-Compress-Raw-Zlib is earlier than 0:2.023-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28825"/>
      <state state_ref="oval:org.mitre.oval:ste:27397"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97766" version="1" comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-119.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29536"/>
      <state state_ref="oval:org.mitre.oval:ste:27018"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98879" version="1" comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3584"/>
      <state state_ref="oval:org.mitre.oval:ste:27315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98824" version="1" comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14774"/>
      <state state_ref="oval:org.mitre.oval:ste:27315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98664" version="1" comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3854"/>
      <state state_ref="oval:org.mitre.oval:ste:27315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98654" version="1" comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3854"/>
      <state state_ref="oval:org.mitre.oval:ste:27618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98649" version="1" comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14555"/>
      <state state_ref="oval:org.mitre.oval:ste:27618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98492" version="1" comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3584"/>
      <state state_ref="oval:org.mitre.oval:ste:27618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98303" version="1" comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14555"/>
      <state state_ref="oval:org.mitre.oval:ste:27315"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98404" version="1" comment="thunderbird is earlier than 0:3.1.15-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26547"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98185" version="1" comment="thunderbird is earlier than 0:2.0.0.24-24.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27105"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98102" version="1" comment="thunderbird is earlier than 0:3.1.12-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27331"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99991" version="1" comment="thunderbird is earlier than 0:3.1.6-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27815"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98310" version="1" comment="rsyslog-gnutls is earlier than 0:4.6.2-3.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30163"/>
      <state state_ref="oval:org.mitre.oval:ste:27117"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98130" version="1" comment="rsyslog-mysql is earlier than 0:4.6.2-3.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29867"/>
      <state state_ref="oval:org.mitre.oval:ste:27117"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98061" version="1" comment="rsyslog-gssapi is earlier than 0:4.6.2-3.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29969"/>
      <state state_ref="oval:org.mitre.oval:ste:27117"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98032" version="1" comment="rsyslog-pgsql is earlier than 0:4.6.2-3.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29691"/>
      <state state_ref="oval:org.mitre.oval:ste:27117"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98028" version="1" comment="rsyslog-relp is earlier than 0:4.6.2-3.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29740"/>
      <state state_ref="oval:org.mitre.oval:ste:27117"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97882" version="1" comment="rsyslog is earlier than 0:4.6.2-3.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29962"/>
      <state state_ref="oval:org.mitre.oval:ste:27117"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98314" version="1" comment="libXfont is earlier than 0:1.4.1-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14504"/>
      <state state_ref="oval:org.mitre.oval:ste:27445"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98313" version="1" comment="libXfont is earlier than 0:1.2.2-1.0.4.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14504"/>
      <state state_ref="oval:org.mitre.oval:ste:27166"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98105" version="1" comment="libXfont-devel is earlier than 0:1.4.1-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14538"/>
      <state state_ref="oval:org.mitre.oval:ste:27445"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97879" version="1" comment="libXfont-devel is earlier than 0:1.2.2-1.0.4.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14538"/>
      <state state_ref="oval:org.mitre.oval:ste:27166"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99017" version="1" comment="kernel-doc is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98999" version="1" comment="kernel-debug is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98997" version="1" comment="kernel-devel is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98943" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98921" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98920" version="1" comment="kernel-firmware is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98849" version="1" comment="kernel is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98678" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98436" version="1" comment="perf is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98261" version="1" comment="kernel-headers is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98238" version="1" comment="python-perf is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98055" version="1" comment="kernel-kdump is earlier than 0:2.6.32-220.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27570"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98223" version="1" comment="qemu-img is earlier than 2:0.12.1.2-2.160.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29180"/>
      <state state_ref="oval:org.mitre.oval:ste:27426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98097" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.160.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:27426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97674" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.160.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29139"/>
      <state state_ref="oval:org.mitre.oval:ste:27426"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98383" version="1" comment="kernel-firmware is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98355" version="1" comment="kernel-kdump is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98292" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98280" version="1" comment="kernel is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98229" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98198" version="1" comment="kernel-headers is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98165" version="1" comment="kernel-debug is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98073" version="1" comment="kernel-devel is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98068" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97938" version="1" comment="perf is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97742" version="1" comment="kernel-doc is earlier than 0:2.6.32-131.12.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27145"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98138" version="1" comment="mutt is earlier than 5:1.5.20-2.20091214hg736b6a.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14378"/>
      <state state_ref="oval:org.mitre.oval:ste:27301"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99981" version="1" comment="systemtap-runtime is earlier than 0:1.1-3.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15292"/>
      <state state_ref="oval:org.mitre.oval:ste:27005"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99969" version="1" comment="systemtap-initscript is earlier than 0:1.1-3.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15362"/>
      <state state_ref="oval:org.mitre.oval:ste:27005"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99942" version="1" comment="systemtap-testsuite is earlier than 0:1.1-3.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14298"/>
      <state state_ref="oval:org.mitre.oval:ste:27005"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99939" version="1" comment="systemtap-initscript is earlier than 0:1.2-11.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15362"/>
      <state state_ref="oval:org.mitre.oval:ste:27746"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99936" version="1" comment="systemtap-server is earlier than 0:1.1-3.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14954"/>
      <state state_ref="oval:org.mitre.oval:ste:27005"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99935" version="1" comment="systemtap-sdt-devel is earlier than 0:1.2-11.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14608"/>
      <state state_ref="oval:org.mitre.oval:ste:27746"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99908" version="1" comment="systemtap-server is earlier than 0:1.2-11.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14954"/>
      <state state_ref="oval:org.mitre.oval:ste:27746"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99854" version="1" comment="systemtap-client is earlier than 0:1.1-3.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15212"/>
      <state state_ref="oval:org.mitre.oval:ste:27005"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99852" version="1" comment="systemtap-testsuite is earlier than 0:1.2-11.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14298"/>
      <state state_ref="oval:org.mitre.oval:ste:27746"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99849" version="1" comment="systemtap-runtime is earlier than 0:1.2-11.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15292"/>
      <state state_ref="oval:org.mitre.oval:ste:27746"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99847" version="1" comment="systemtap-client is earlier than 0:1.2-11.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15212"/>
      <state state_ref="oval:org.mitre.oval:ste:27746"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99833" version="1" comment="systemtap is earlier than 0:1.1-3.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15026"/>
      <state state_ref="oval:org.mitre.oval:ste:27005"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99529" version="1" comment="systemtap-grapher is earlier than 0:1.2-11.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30332"/>
      <state state_ref="oval:org.mitre.oval:ste:27746"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99429" version="1" comment="systemtap is earlier than 0:1.2-11.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15026"/>
      <state state_ref="oval:org.mitre.oval:ste:27746"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100006" version="1" comment="systemtap-sdt-devel is earlier than 0:1.1-3.el5_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14608"/>
      <state state_ref="oval:org.mitre.oval:ste:27005"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98530" version="1" comment="nss is earlier than 0:3.12.9-12.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:27321"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98482" version="1" comment="nss-sysinit is earlier than 0:3.12.9-12.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:27321"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98470" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.10-4.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:27236"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98459" version="1" comment="nspr is earlier than 0:4.8.8-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:26787"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98382" version="1" comment="nss-devel is earlier than 0:3.12.9-12.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:27321"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98362" version="1" comment="nss-devel is earlier than 0:3.12.10-4.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:27236"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98343" version="1" comment="nss-tools is earlier than 0:3.12.10-4.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:27236"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98293" version="1" comment="nss is earlier than 0:3.12.10-4.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:27236"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98271" version="1" comment="nss-tools is earlier than 0:3.12.9-12.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:27321"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98140" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.9-12.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:27321"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98043" version="1" comment="nspr-devel is earlier than 0:4.8.8-1.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:26787"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98478" version="1" comment="flash-plugin is earlier than 0:10.3.183.10-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27002"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98466" version="1" comment="flash-plugin is earlier than 0:10.3.183.10-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27231"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99896" version="1" comment="augeas is earlier than 0:1.0.0-5.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30397"/>
      <state state_ref="oval:org.mitre.oval:ste:27948"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100343" version="1" comment="augeas-devel is earlier than 0:1.0.0-5.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30286"/>
      <state state_ref="oval:org.mitre.oval:ste:27948"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100284" version="1" comment="augeas-libs is earlier than 0:1.0.0-5.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30408"/>
      <state state_ref="oval:org.mitre.oval:ste:27948"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99015" version="1" comment="openssl-devel is earlier than 0:1.0.1e-16.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:27511"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98928" version="1" comment="openssl-perl is earlier than 0:1.0.1e-16.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:27511"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98888" version="1" comment="openssl is earlier than 0:1.0.1e-16.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:27511"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98827" version="1" comment="openssl-static is earlier than 0:1.0.1e-16.el6_5.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:27511"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98647" version="1" comment="krb5-devel is earlier than 0:1.9-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:26766"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98596" version="1" comment="krb5-server-ldap is earlier than 0:1.9-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29451"/>
      <state state_ref="oval:org.mitre.oval:ste:26766"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98584" version="1" comment="krb5-workstation is earlier than 0:1.9-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:26766"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98573" version="1" comment="krb5-libs is earlier than 0:1.9-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:26766"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98325" version="1" comment="krb5 is earlier than 0:1.9-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14120"/>
      <state state_ref="oval:org.mitre.oval:ste:26766"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98298" version="1" comment="krb5-server is earlier than 0:1.9-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:26766"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98259" version="1" comment="krb5-pkinit-openssl is earlier than 0:1.9-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29392"/>
      <state state_ref="oval:org.mitre.oval:ste:26766"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98556" version="1" comment="cyrus-imapd-utils is earlier than 0:2.3.7-12.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14555"/>
      <state state_ref="oval:org.mitre.oval:ste:26819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98476" version="1" comment="cyrus-imapd-perl is earlier than 0:2.3.7-12.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14774"/>
      <state state_ref="oval:org.mitre.oval:ste:26819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98340" version="1" comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14555"/>
      <state state_ref="oval:org.mitre.oval:ste:27491"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98322" version="1" comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3584"/>
      <state state_ref="oval:org.mitre.oval:ste:27491"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98308" version="1" comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3854"/>
      <state state_ref="oval:org.mitre.oval:ste:27491"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98033" version="1" comment="cyrus-imapd is earlier than 0:2.3.7-12.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3854"/>
      <state state_ref="oval:org.mitre.oval:ste:26819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97968" version="1" comment="cyrus-imapd-devel is earlier than 0:2.3.7-12.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3584"/>
      <state state_ref="oval:org.mitre.oval:ste:26819"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98793" version="1" comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:27362"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98666" version="1" comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:27423"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98490" version="1" comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:27362"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98484" version="1" comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:27423"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98461" version="1" comment="freetype is earlier than 0:2.2.1-28.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:27362"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98425" version="1" comment="freetype is earlier than 0:2.3.11-6.el6_1.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:27423"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98614" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:27269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98603" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.29-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:27528"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98552" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:27528"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98537" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:27528"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98371" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:27269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98250" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.29-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:27269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98228" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.29-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:27269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98149" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:27269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98142" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.29-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:27528"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97996" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:27528"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97901" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.29-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:27269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97694" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.29-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:27528"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98241" version="1" comment="bind is earlier than 32:9.7.3-2.el6_1.P3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:27294"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98104" version="1" comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:27294"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97731" version="1" comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:27294"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97693" version="1" comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:27294"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97309" version="1" comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:27294"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97308" version="1" comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:27294"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137856" version="1" comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29448"/>
      <state state_ref="oval:org.mitre.oval:ste:37264"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137804" version="1" comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29237"/>
      <state state_ref="oval:org.mitre.oval:ste:37264"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137574" version="1" comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28577"/>
      <state state_ref="oval:org.mitre.oval:ste:37264"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137380" version="1" comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29535"/>
      <state state_ref="oval:org.mitre.oval:ste:37264"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137310" version="1" comment="bind-debuginfo is earlier than 32:9.7.3-2.el6_1.P3.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43450"/>
      <state state_ref="oval:org.mitre.oval:ste:37235"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137289" version="1" comment="bind97 is earlier than 32:9.7.0-6.P2.el5_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28886"/>
      <state state_ref="oval:org.mitre.oval:ste:37264"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98813" version="1" comment="squid is earlier than 7:3.1.10-1.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14403"/>
      <state state_ref="oval:org.mitre.oval:ste:27268"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98282" version="1" comment="NetworkManager-glib is earlier than 1:0.8.1-9.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14206"/>
      <state state_ref="oval:org.mitre.oval:ste:27102"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98277" version="1" comment="NetworkManager-devel is earlier than 1:0.8.1-9.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14736"/>
      <state state_ref="oval:org.mitre.oval:ste:27102"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98253" version="1" comment="NetworkManager is earlier than 1:0.8.1-9.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15163"/>
      <state state_ref="oval:org.mitre.oval:ste:27102"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97993" version="1" comment="NetworkManager-glib-devel is earlier than 1:0.8.1-9.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15012"/>
      <state state_ref="oval:org.mitre.oval:ste:27102"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97387" version="1" comment="NetworkManager-gnome is earlier than 1:0.8.1-9.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15031"/>
      <state state_ref="oval:org.mitre.oval:ste:27102"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98455" version="1" comment="httpd-devel is earlier than 0:2.2.3-53.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:27494"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98451" version="1" comment="httpd is earlier than 0:2.2.3-53.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:27494"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98374" version="1" comment="httpd-manual is earlier than 0:2.2.15-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:27328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98331" version="1" comment="httpd-devel is earlier than 0:2.2.15-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:27328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98122" version="1" comment="httpd-tools is earlier than 0:2.2.15-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29273"/>
      <state state_ref="oval:org.mitre.oval:ste:27328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98108" version="1" comment="mod_ssl is earlier than 0:2.2.15-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:27328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98060" version="1" comment="httpd-manual is earlier than 0:2.2.3-53.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:27494"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97962" version="1" comment="mod_ssl is earlier than 0:2.2.3-53.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:27494"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97781" version="1" comment="httpd is earlier than 0:2.2.15-9.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:27328"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98350" version="1" comment="dhcp-devel is earlier than 12:4.1.1-19.P1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3630"/>
      <state state_ref="oval:org.mitre.oval:ste:27420"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98225" version="1" comment="dhcp-devel is earlier than 12:3.0.5-29.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3630"/>
      <state state_ref="oval:org.mitre.oval:ste:26752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98224" version="1" comment="libdhcp4client-devel is earlier than 12:3.0.5-29.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30275"/>
      <state state_ref="oval:org.mitre.oval:ste:26752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98139" version="1" comment="dhcp is earlier than 12:3.0.5-29.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3459"/>
      <state state_ref="oval:org.mitre.oval:ste:26752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98083" version="1" comment="dhclient is earlier than 12:3.0.5-29.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15218"/>
      <state state_ref="oval:org.mitre.oval:ste:26752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97914" version="1" comment="libdhcp4client is earlier than 12:3.0.5-29.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30184"/>
      <state state_ref="oval:org.mitre.oval:ste:26752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97580" version="1" comment="dhclient is earlier than 12:4.1.1-19.P1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15218"/>
      <state state_ref="oval:org.mitre.oval:ste:27420"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97365" version="1" comment="dhcp is earlier than 12:4.1.1-19.P1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3459"/>
      <state state_ref="oval:org.mitre.oval:ste:27420"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98595" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98561" version="1" comment="kernel-headers is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98535" version="1" comment="perf is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98406" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98375" version="1" comment="kernel-firmware is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98317" version="1" comment="kernel-debug is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98257" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98256" version="1" comment="kernel-kdump is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97989" version="1" comment="kernel-devel is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97881" version="1" comment="kernel-doc is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97710" version="1" comment="kernel is earlier than 0:2.6.32-131.17.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27368"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99743" version="1" comment="wireshark-devel is earlier than 0:1.2.13-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30148"/>
      <state state_ref="oval:org.mitre.oval:ste:27515"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99663" version="1" comment="wireshark is earlier than 0:1.2.13-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:27515"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99502" version="1" comment="wireshark-gnome is earlier than 0:1.2.13-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:27515"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98430" version="1" comment="squid is earlier than 7:3.1.10-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14403"/>
      <state state_ref="oval:org.mitre.oval:ste:27113"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98136" version="1" comment="xerces-j2 is earlier than 0:2.7.1-12.6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15189"/>
      <state state_ref="oval:org.mitre.oval:ste:27443"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98126" version="1" comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-12.6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14818"/>
      <state state_ref="oval:org.mitre.oval:ste:27443"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98027" version="1" comment="xerces-j2-demo is earlier than 0:2.7.1-12.6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15310"/>
      <state state_ref="oval:org.mitre.oval:ste:27443"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97783" version="1" comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-12.6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14775"/>
      <state state_ref="oval:org.mitre.oval:ste:27443"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97434" version="1" comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-12.6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14948"/>
      <state state_ref="oval:org.mitre.oval:ste:27443"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97371" version="1" comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-12.6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15179"/>
      <state state_ref="oval:org.mitre.oval:ste:27443"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97357" version="1" comment="xerces-j2-scripts is earlier than 0:2.7.1-12.6.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14314"/>
      <state state_ref="oval:org.mitre.oval:ste:27443"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98895" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.160.el6_1.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:27179"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98882" version="1" comment="qemu-img is earlier than 2:0.12.1.2-2.160.el6_1.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29180"/>
      <state state_ref="oval:org.mitre.oval:ste:27179"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98781" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.160.el6_1.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29139"/>
      <state state_ref="oval:org.mitre.oval:ste:27179"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98123" version="1" comment="flash-plugin is earlier than 0:10.3.183.5-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27406"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97648" version="1" comment="flash-plugin is earlier than 0:10.3.183.5-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99927" version="1" comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29451"/>
      <state state_ref="oval:org.mitre.oval:ste:27858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99864" version="1" comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:27858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99817" version="1" comment="krb5-server is earlier than 0:1.8.2-3.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:27858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99748" version="1" comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29392"/>
      <state state_ref="oval:org.mitre.oval:ste:27858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99061" version="1" comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:27858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99027" version="1" comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:27858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100011" version="1" comment="krb5 is earlier than 0:1.8.2-3.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14120"/>
      <state state_ref="oval:org.mitre.oval:ste:27858"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98315" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:27286"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98262" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:27241"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98167" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.2-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:27241"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98162" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.2-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:27286"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98127" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:27286"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98087" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.2-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:27241"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98077" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:27286"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98074" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.2-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:27241"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97984" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:27241"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97953" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.2-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:27286"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97888" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:27286"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97859" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:27286"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97525" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.2-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:27241"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97323" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.2-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:27241"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97311" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.2-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:27241"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98402" version="1" comment="dovecot is earlier than 0:1.0.7-7.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3572"/>
      <state state_ref="oval:org.mitre.oval:ste:27399"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98363" version="1" comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30040"/>
      <state state_ref="oval:org.mitre.oval:ste:27482"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98243" version="1" comment="dovecot-devel is earlier than 1:2.0.9-2.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4212"/>
      <state state_ref="oval:org.mitre.oval:ste:27482"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98119" version="1" comment="dovecot is earlier than 1:2.0.9-2.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3572"/>
      <state state_ref="oval:org.mitre.oval:ste:27482"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98088" version="1" comment="dovecot-mysql is earlier than 1:2.0.9-2.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29698"/>
      <state state_ref="oval:org.mitre.oval:ste:27482"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98082" version="1" comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30241"/>
      <state state_ref="oval:org.mitre.oval:ste:27482"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98859" version="1" comment="ipa-python is earlier than 0:2.1.3-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28763"/>
      <state state_ref="oval:org.mitre.oval:ste:27359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98856" version="1" comment="ipa is earlier than 0:2.1.3-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28864"/>
      <state state_ref="oval:org.mitre.oval:ste:27359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98591" version="1" comment="ipa-admintools is earlier than 0:2.1.3-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28810"/>
      <state state_ref="oval:org.mitre.oval:ste:27359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98565" version="1" comment="ipa-server-selinux is earlier than 0:2.1.3-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29082"/>
      <state state_ref="oval:org.mitre.oval:ste:27359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98468" version="1" comment="ipa-client is earlier than 0:2.1.3-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29240"/>
      <state state_ref="oval:org.mitre.oval:ste:27359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98364" version="1" comment="ipa-server is earlier than 0:2.1.3-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28996"/>
      <state state_ref="oval:org.mitre.oval:ste:27359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98295" version="1" comment="kernel-kdump is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98290" version="1" comment="kernel is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98286" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98273" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98255" version="1" comment="perf is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98251" version="1" comment="kernel-doc is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98236" version="1" comment="kernel-firmware is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98232" version="1" comment="kernel-headers is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98030" version="1" comment="kernel-devel is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97921" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97728" version="1" comment="kernel-debug is earlier than 0:2.6.32-131.6.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98252" version="1" comment="tigervnc-server-applet is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29809"/>
      <state state_ref="oval:org.mitre.oval:ste:27449"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97963" version="1" comment="tigervnc is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29787"/>
      <state state_ref="oval:org.mitre.oval:ste:27449"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97645" version="1" comment="tigervnc-server-module is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30173"/>
      <state state_ref="oval:org.mitre.oval:ste:27449"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97471" version="1" comment="tigervnc-server is earlier than 0:1.0.90-0.15.20110314svn4359.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30079"/>
      <state state_ref="oval:org.mitre.oval:ste:27449"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97929" version="1" comment="thunderbird is earlier than 0:2.0.0.24-25.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27413"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97563" version="1" comment="thunderbird is earlier than 0:3.1.14-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26977"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97850" version="1" comment="ca-certificates is earlier than 0:2010.63-3.el6_1.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29046"/>
      <state state_ref="oval:org.mitre.oval:ste:27178"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97617" version="1" comment="quagga-devel is earlier than 0:0.99.15-5.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14340"/>
      <state state_ref="oval:org.mitre.oval:ste:27246"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97438" version="1" comment="quagga-contrib is earlier than 0:0.99.15-5.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14111"/>
      <state state_ref="oval:org.mitre.oval:ste:27246"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96846" version="1" comment="quagga is earlier than 0:0.99.15-5.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14268"/>
      <state state_ref="oval:org.mitre.oval:ste:27246"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98053" version="1" comment="tomcat6-webapps is earlier than 0:6.0.24-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29371"/>
      <state state_ref="oval:org.mitre.oval:ste:27223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98042" version="1" comment="tomcat6-lib is earlier than 0:6.0.24-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29391"/>
      <state state_ref="oval:org.mitre.oval:ste:27223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98015" version="1" comment="tomcat6-docs-webapp is earlier than 0:6.0.24-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29374"/>
      <state state_ref="oval:org.mitre.oval:ste:27223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97837" version="1" comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29298"/>
      <state state_ref="oval:org.mitre.oval:ste:27223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97776" version="1" comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29382"/>
      <state state_ref="oval:org.mitre.oval:ste:27223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97643" version="1" comment="tomcat6-javadoc is earlier than 0:6.0.24-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28454"/>
      <state state_ref="oval:org.mitre.oval:ste:27223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97499" version="1" comment="tomcat6 is earlier than 0:6.0.24-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29276"/>
      <state state_ref="oval:org.mitre.oval:ste:27223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97473" version="1" comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29264"/>
      <state state_ref="oval:org.mitre.oval:ste:27223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97288" version="1" comment="tomcat6-admin-webapps is earlier than 0:6.0.24-33.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28477"/>
      <state state_ref="oval:org.mitre.oval:ste:27223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97686" version="1" comment="libtiff is earlier than 0:3.9.4-1.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:26946"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97675" version="1" comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:26946"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97433" version="1" comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30004"/>
      <state state_ref="oval:org.mitre.oval:ste:26946"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99839" version="1" comment="openswan-doc is earlier than 0:2.6.24-8.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15278"/>
      <state state_ref="oval:org.mitre.oval:ste:27740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100008" version="1" comment="openswan is earlier than 0:2.6.24-8.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14994"/>
      <state state_ref="oval:org.mitre.oval:ste:27740"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98700" version="1" comment="freetype-demos is earlier than 0:2.3.11-6.el6_1.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:27140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98660" version="1" comment="freetype-demos is earlier than 0:2.2.1-28.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:27021"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98563" version="1" comment="freetype-devel is earlier than 0:2.3.11-6.el6_1.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:27140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98536" version="1" comment="freetype is earlier than 0:2.2.1-28.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:27021"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98188" version="1" comment="freetype-devel is earlier than 0:2.2.1-28.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:27021"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98065" version="1" comment="freetype is earlier than 0:2.3.11-6.el6_1.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:27140"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98062" version="1" comment="gimp-devel-tools is earlier than 2:2.6.9-4.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29218"/>
      <state state_ref="oval:org.mitre.oval:ste:27265"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98036" version="1" comment="gimp-devel is earlier than 2:2.6.9-4.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4711"/>
      <state state_ref="oval:org.mitre.oval:ste:27265"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98008" version="1" comment="gimp-libs is earlier than 2:2.6.9-4.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14790"/>
      <state state_ref="oval:org.mitre.oval:ste:27265"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97987" version="1" comment="gimp-help-browser is earlier than 2:2.6.9-4.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29490"/>
      <state state_ref="oval:org.mitre.oval:ste:27265"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97692" version="1" comment="gimp is earlier than 2:2.6.9-4.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:5002"/>
      <state state_ref="oval:org.mitre.oval:ste:27265"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99983" version="1" comment="xulrunner is earlier than 0:1.9.2.13-3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27852"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99947" version="1" comment="firefox is earlier than 0:3.6.13-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27693"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99608" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27852"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100126" version="1" comment="firefox is earlier than 0:3.6.13-2.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100121" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.13-3.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27584"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100021" version="1" comment="xulrunner is earlier than 0:1.9.2.13-3.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27584"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97869" version="1" comment="libvirt is earlier than 0:0.8.1-27.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15209"/>
      <state state_ref="oval:org.mitre.oval:ste:27334"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97753" version="1" comment="libvirt-python is earlier than 0:0.8.1-27.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15191"/>
      <state state_ref="oval:org.mitre.oval:ste:27334"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97555" version="1" comment="libvirt-client is earlier than 0:0.8.1-27.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29031"/>
      <state state_ref="oval:org.mitre.oval:ste:27334"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97305" version="1" comment="libvirt-devel is earlier than 0:0.8.1-27.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14880"/>
      <state state_ref="oval:org.mitre.oval:ste:27334"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98622" version="1" comment="xorg-x11-server-source is earlier than 0:1.7.7-29.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28734"/>
      <state state_ref="oval:org.mitre.oval:ste:27627"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98602" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.76.el5_7.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:27495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98585" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.76.el5_7.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:27495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98579" version="1" comment="xorg-x11-server-Xnest is earlier than 0:1.7.7-29.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14794"/>
      <state state_ref="oval:org.mitre.oval:ste:27627"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98548" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.76.el5_7.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:27495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98518" version="1" comment="xorg-x11-server-Xorg is earlier than 0:1.7.7-29.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14653"/>
      <state state_ref="oval:org.mitre.oval:ste:27627"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98513" version="1" comment="xorg-x11-server is earlier than 0:1.1.1-48.76.el5_7.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14418"/>
      <state state_ref="oval:org.mitre.oval:ste:27495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98509" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.7.7-29.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:27627"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98416" version="1" comment="xorg-x11-server-Xephyr is earlier than 0:1.7.7-29.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14842"/>
      <state state_ref="oval:org.mitre.oval:ste:27627"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98366" version="1" comment="xorg-x11-server-common is earlier than 0:1.7.7-29.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28695"/>
      <state state_ref="oval:org.mitre.oval:ste:27627"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98353" version="1" comment="xorg-x11-server-Xvnc-source is earlier than 0:1.1.1-48.76.el5_7.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14667"/>
      <state state_ref="oval:org.mitre.oval:ste:27495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98218" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.76.el5_7.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:27495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98092" version="1" comment="xorg-x11-server-devel is earlier than 0:1.7.7-29.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28915"/>
      <state state_ref="oval:org.mitre.oval:ste:27627"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98052" version="1" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.76.el5_7.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14353"/>
      <state state_ref="oval:org.mitre.oval:ste:27495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97946" version="1" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.76.el5_7.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14873"/>
      <state state_ref="oval:org.mitre.oval:ste:27495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97703" version="1" comment="xorg-x11-server-Xvfb is earlier than 0:1.7.7-29.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14709"/>
      <state state_ref="oval:org.mitre.oval:ste:27627"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97660" version="1" comment="xorg-x11-server is earlier than 0:1.7.7-29.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14418"/>
      <state state_ref="oval:org.mitre.oval:ste:27627"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98056" version="1" comment="apr-docs is earlier than 0:1.2.7-11.el5_6.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15034"/>
      <state state_ref="oval:org.mitre.oval:ste:27056"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98041" version="1" comment="apr is earlier than 0:1.2.7-11.el5_6.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15116"/>
      <state state_ref="oval:org.mitre.oval:ste:27056"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97916" version="1" comment="apr is earlier than 0:1.3.9-3.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15116"/>
      <state state_ref="oval:org.mitre.oval:ste:27143"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97827" version="1" comment="apr-devel is earlier than 0:1.3.9-3.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15174"/>
      <state state_ref="oval:org.mitre.oval:ste:27143"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97722" version="1" comment="apr-devel is earlier than 0:1.2.7-11.el5_6.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15174"/>
      <state state_ref="oval:org.mitre.oval:ste:27056"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97654" version="1" comment="flash-plugin is earlier than 0:10.2.153.1-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27230"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97632" version="1" comment="flash-plugin is earlier than 0:10.2.153.1-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27281"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100624" version="1" comment="mysql-embedded-devel is earlier than 0:5.1.73-3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28807"/>
      <state state_ref="oval:org.mitre.oval:ste:27959"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100589" version="1" comment="mysql-test is earlier than 0:5.1.73-3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14941"/>
      <state state_ref="oval:org.mitre.oval:ste:27959"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100580" version="1" comment="mysql-devel is earlier than 0:5.1.73-3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14481"/>
      <state state_ref="oval:org.mitre.oval:ste:27959"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100506" version="1" comment="mysql-embedded is earlier than 0:5.1.73-3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28870"/>
      <state state_ref="oval:org.mitre.oval:ste:27959"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100277" version="1" comment="mysql-server is earlier than 0:5.1.73-3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14342"/>
      <state state_ref="oval:org.mitre.oval:ste:27959"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100229" version="1" comment="mysql-bench is earlier than 0:5.1.73-3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14400"/>
      <state state_ref="oval:org.mitre.oval:ste:27959"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100202" version="1" comment="mysql is earlier than 0:5.1.73-3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14355"/>
      <state state_ref="oval:org.mitre.oval:ste:27959"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100043" version="1" comment="mysql-libs is earlier than 0:5.1.73-3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28723"/>
      <state state_ref="oval:org.mitre.oval:ste:27959"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97550" version="1" comment="kdenetwork-devel is earlier than 7:4.3.4-11.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14299"/>
      <state state_ref="oval:org.mitre.oval:ste:27191"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97457" version="1" comment="kdenetwork is earlier than 7:4.3.4-11.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14300"/>
      <state state_ref="oval:org.mitre.oval:ste:27191"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96887" version="1" comment="kdenetwork-libs is earlier than 7:4.3.4-11.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29880"/>
      <state state_ref="oval:org.mitre.oval:ste:27191"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98203" version="1" comment="libsoup-devel is earlier than 0:2.28.2-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15129"/>
      <state state_ref="oval:org.mitre.oval:ste:26810"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97745" version="1" comment="libsoup is earlier than 0:2.28.2-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15103"/>
      <state state_ref="oval:org.mitre.oval:ste:26810"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98589" version="1" comment="NetworkManager-glib is earlier than 1:0.8.1-9.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14206"/>
      <state state_ref="oval:org.mitre.oval:ste:27295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98582" version="1" comment="NetworkManager is earlier than 1:0.8.1-9.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15163"/>
      <state state_ref="oval:org.mitre.oval:ste:27295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98403" version="1" comment="NetworkManager-gnome is earlier than 1:0.8.1-9.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15031"/>
      <state state_ref="oval:org.mitre.oval:ste:27295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98319" version="1" comment="NetworkManager-devel is earlier than 1:0.8.1-9.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14736"/>
      <state state_ref="oval:org.mitre.oval:ste:27295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97979" version="1" comment="NetworkManager-glib-devel is earlier than 1:0.8.1-9.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15012"/>
      <state state_ref="oval:org.mitre.oval:ste:27295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97425" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.39.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:27253"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97082" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.39.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:27253"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97074" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.39.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:27253"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97073" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.39.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:27253"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96965" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.39.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:27253"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137864" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.20.b17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:37822"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137829" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.20.b17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:37822"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137774" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.20.b17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:37822"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137660" version="1" comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.0-1.39.b17.el6_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42919"/>
      <state state_ref="oval:org.mitre.oval:ste:37241"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137586" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.20.b17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:37822"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137485" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.20.b17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:37822"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97741" version="1" comment="gdm-user-switch-applet is earlier than 1:2.30.4-21.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30120"/>
      <state state_ref="oval:org.mitre.oval:ste:27165"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97623" version="1" comment="gdm-plugin-fingerprint is earlier than 1:2.30.4-21.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30171"/>
      <state state_ref="oval:org.mitre.oval:ste:27165"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97604" version="1" comment="gdm is earlier than 1:2.30.4-21.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14698"/>
      <state state_ref="oval:org.mitre.oval:ste:27165"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97415" version="1" comment="gdm-plugin-smartcard is earlier than 1:2.30.4-21.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30274"/>
      <state state_ref="oval:org.mitre.oval:ste:27165"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97395" version="1" comment="gdm-libs is earlier than 1:2.30.4-21.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29906"/>
      <state state_ref="oval:org.mitre.oval:ste:27165"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98789" version="1" comment="nss-sysinit is earlier than 0:3.12.10-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:27242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98760" version="1" comment="nspr is earlier than 0:4.8.8-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:27558"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98752" version="1" comment="nss-devel is earlier than 0:3.12.10-7.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:27428"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98738" version="1" comment="nspr-devel is earlier than 0:4.8.8-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:27558"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98650" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.10-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:27242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98627" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.10-7.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:27428"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98626" version="1" comment="nss-devel is earlier than 0:3.12.10-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:27242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98621" version="1" comment="nss-util is earlier than 0:3.12.10-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:27322"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98540" version="1" comment="nss-util-devel is earlier than 0:3.12.10-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:27322"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98531" version="1" comment="nss is earlier than 0:3.12.10-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:27242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98465" version="1" comment="nss is earlier than 0:3.12.10-7.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:27428"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98434" version="1" comment="nss-tools is earlier than 0:3.12.10-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:27242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97792" version="1" comment="nss-tools is earlier than 0:3.12.10-7.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:27428"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98332" version="1" comment="icedtea-web is earlier than 0:1.0.4-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29552"/>
      <state state_ref="oval:org.mitre.oval:ste:27027"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98296" version="1" comment="icedtea-web-javadoc is earlier than 0:1.0.4-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29549"/>
      <state state_ref="oval:org.mitre.oval:ste:27027"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97830" version="1" comment="perf is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97829" version="1" comment="kernel-doc is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97824" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97787" version="1" comment="kernel-devel is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97775" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97715" version="1" comment="kernel-kdump is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97644" version="1" comment="kernel is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97621" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97593" version="1" comment="kernel-firmware is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97363" version="1" comment="kernel-debug is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97326" version="1" comment="kernel-headers is earlier than 0:2.6.32-71.29.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27029"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97967" version="1" comment="qemu-img is earlier than 2:0.12.1.2-2.160.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29180"/>
      <state state_ref="oval:org.mitre.oval:ste:27339"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97842" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.160.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:27339"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96982" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.160.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29139"/>
      <state state_ref="oval:org.mitre.oval:ste:27339"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97721" version="1" comment="rdesktop is earlier than 0:1.6.0-8.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14647"/>
      <state state_ref="oval:org.mitre.oval:ste:26889"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137855" version="1" comment="rdesktop-debuginfo is earlier than 0:1.6.0-8.el6_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43419"/>
      <state state_ref="oval:org.mitre.oval:ste:38177"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137607" version="1" comment="rdesktop is earlier than 0:1.6.0-3.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14647"/>
      <state state_ref="oval:org.mitre.oval:ste:37783"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98175" version="1" comment="libcurl-devel is earlier than 0:7.19.7-26.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28736"/>
      <state state_ref="oval:org.mitre.oval:ste:27077"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97809" version="1" comment="curl is earlier than 0:7.19.7-26.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14575"/>
      <state state_ref="oval:org.mitre.oval:ste:27077"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97421" version="1" comment="libcurl is earlier than 0:7.19.7-26.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28912"/>
      <state state_ref="oval:org.mitre.oval:ste:27077"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137724" version="1" comment="curl is earlier than 0:7.15.5-9.el5_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14575"/>
      <state state_ref="oval:org.mitre.oval:ste:38092"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137578" version="1" comment="curl-debuginfo is earlier than 0:7.19.7-26.el6_1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3487"/>
      <state state_ref="oval:org.mitre.oval:ste:37885"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137150" version="1" comment="curl-devel is earlier than 0:7.15.5-9.el5_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14469"/>
      <state state_ref="oval:org.mitre.oval:ste:38092"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97229" version="1" comment="mysql-embedded-devel is earlier than 0:5.1.52-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28807"/>
      <state state_ref="oval:org.mitre.oval:ste:27120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97218" version="1" comment="mysql-devel is earlier than 0:5.1.52-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14481"/>
      <state state_ref="oval:org.mitre.oval:ste:27120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97142" version="1" comment="mysql is earlier than 0:5.1.52-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14355"/>
      <state state_ref="oval:org.mitre.oval:ste:27120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97124" version="1" comment="mysql-libs is earlier than 0:5.1.52-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28723"/>
      <state state_ref="oval:org.mitre.oval:ste:27120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97081" version="1" comment="mysql-server is earlier than 0:5.1.52-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14342"/>
      <state state_ref="oval:org.mitre.oval:ste:27120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96993" version="1" comment="mysql-test is earlier than 0:5.1.52-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14941"/>
      <state state_ref="oval:org.mitre.oval:ste:27120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96978" version="1" comment="mysql-embedded is earlier than 0:5.1.52-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28870"/>
      <state state_ref="oval:org.mitre.oval:ste:27120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96839" version="1" comment="mysql-bench is earlier than 0:5.1.52-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14400"/>
      <state state_ref="oval:org.mitre.oval:ste:27120"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97391" version="1" comment="rsync is earlier than 0:3.0.6-5.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:959"/>
      <state state_ref="oval:org.mitre.oval:ste:26372"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97384" version="1" comment="flash-plugin is earlier than 0:10.3.181.14-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97214" version="1" comment="flash-plugin is earlier than 0:10.3.181.14-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27222"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97101" version="1" comment="mailman is earlier than 3:2.1.12-14.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14521"/>
      <state state_ref="oval:org.mitre.oval:ste:27227"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97633" version="1" comment="dbus-libs is earlier than 0:1.1.2-15.el5_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15234"/>
      <state state_ref="oval:org.mitre.oval:ste:26611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97598" version="1" comment="dbus is earlier than 0:1.1.2-15.el5_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14213"/>
      <state state_ref="oval:org.mitre.oval:ste:26611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97597" version="1" comment="dbus-devel is earlier than 1:1.2.24-4.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14425"/>
      <state state_ref="oval:org.mitre.oval:ste:27168"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97572" version="1" comment="dbus-x11 is earlier than 1:1.2.24-4.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14132"/>
      <state state_ref="oval:org.mitre.oval:ste:27168"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97533" version="1" comment="dbus is earlier than 1:1.2.24-4.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14213"/>
      <state state_ref="oval:org.mitre.oval:ste:27168"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97463" version="1" comment="dbus-devel is earlier than 0:1.1.2-15.el5_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14425"/>
      <state state_ref="oval:org.mitre.oval:ste:26611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97366" version="1" comment="dbus-libs is earlier than 1:1.2.24-4.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15234"/>
      <state state_ref="oval:org.mitre.oval:ste:27168"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97339" version="1" comment="dbus-x11 is earlier than 0:1.1.2-15.el5_6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14132"/>
      <state state_ref="oval:org.mitre.oval:ste:26611"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96980" version="1" comment="dbus-doc is earlier than 1:1.2.24-4.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30088"/>
      <state state_ref="oval:org.mitre.oval:ste:27168"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97805" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97793" version="1" comment="kernel-headers is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97759" version="1" comment="perf is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97687" version="1" comment="kernel-kdump is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97666" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97634" version="1" comment="kernel-devel is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97618" version="1" comment="kernel-firmware is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97413" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97319" version="1" comment="kernel-doc is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97310" version="1" comment="kernel is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97103" version="1" comment="kernel-debug is earlier than 0:2.6.32-71.24.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27007"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99034" version="1" comment="libXfont-devel is earlier than 0:1.4.5-3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14538"/>
      <state state_ref="oval:org.mitre.oval:ste:26753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98834" version="1" comment="libXfont is earlier than 0:1.4.5-3.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14504"/>
      <state state_ref="oval:org.mitre.oval:ste:26753"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98673" version="1" comment="libXfont-devel is earlier than 0:1.2.2-1.0.5.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14538"/>
      <state state_ref="oval:org.mitre.oval:ste:27552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98412" version="1" comment="libXfont is earlier than 0:1.2.2-1.0.5.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14504"/>
      <state state_ref="oval:org.mitre.oval:ste:27552"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97664" version="1" comment="libtiff-devel is earlier than 0:3.8.2-7.el5_6.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:27169"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97547" version="1" comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:27266"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97237" version="1" comment="libtiff is earlier than 0:3.8.2-7.el5_6.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:27169"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96834" version="1" comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30004"/>
      <state state_ref="oval:org.mitre.oval:ste:27266"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96686" version="1" comment="libtiff is earlier than 0:3.9.4-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:27266"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97247" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:26855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97213" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:27061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97204" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:27061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97172" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:26855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97146" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:27061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97121" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:27061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97095" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:27061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97086" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:26855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97084" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:26855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96918" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:26855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96913" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:27061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96911" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:27061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96896" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:27061"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96819" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:26855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96683" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:26855"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97716" version="1" comment="postfix is earlier than 2:2.6.6-2.2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1466"/>
      <state state_ref="oval:org.mitre.oval:ste:26495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97683" version="1" comment="postfix-perl-scripts is earlier than 2:2.6.6-2.2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30198"/>
      <state state_ref="oval:org.mitre.oval:ste:26495"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137547" version="1" comment="postfix-debuginfo is earlier than 2:2.6.6-2.2.el6_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43348"/>
      <state state_ref="oval:org.mitre.oval:ste:38242"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137246" version="1" comment="postfix-pflogsumm is earlier than 2:2.3.3-2.3.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14593"/>
      <state state_ref="oval:org.mitre.oval:ste:38195"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136888" version="1" comment="postfix is earlier than 2:2.3.3-2.3.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1466"/>
      <state state_ref="oval:org.mitre.oval:ste:38195"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97568" version="1" comment="samba-doc is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29416"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97567" version="1" comment="samba-winbind-devel is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29445"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97558" version="1" comment="libsmbclient is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15389"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97542" version="1" comment="samba-swat is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97507" version="1" comment="samba-winbind-clients is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29486"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97488" version="1" comment="samba-domainjoin-gui is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97466" version="1" comment="samba-client is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97333" version="1" comment="samba is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97325" version="1" comment="samba-winbind is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29389"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97294" version="1" comment="libsmbclient-devel is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97255" version="1" comment="samba-common is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14032"/>
      <state state_ref="oval:org.mitre.oval:ste:27228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137854" version="1" comment="samba is earlier than 0:3.0.33-3.29.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:38173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137852" version="1" comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15389"/>
      <state state_ref="oval:org.mitre.oval:ste:38173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137782" version="1" comment="samba-swat is earlier than 0:3.0.33-3.29.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:38173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137757" version="1" comment="samba-common is earlier than 0:3.0.33-3.29.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14032"/>
      <state state_ref="oval:org.mitre.oval:ste:38173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137684" version="1" comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:38173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137366" version="1" comment="samba-debuginfo is earlier than 0:3.5.4-68.el6_0.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43284"/>
      <state state_ref="oval:org.mitre.oval:ste:38223"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137175" version="1" comment="samba-client is earlier than 0:3.0.33-3.29.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:38173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99974" version="1" comment="postgresql-plpython is earlier than 0:8.4.5-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29607"/>
      <state state_ref="oval:org.mitre.oval:ste:27557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99929" version="1" comment="postgresql-contrib is earlier than 0:8.4.5-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:27557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99923" version="1" comment="postgresql-devel is earlier than 0:8.4.5-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:27557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99917" version="1" comment="postgresql-test is earlier than 0:8.4.5-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:27557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99851" version="1" comment="postgresql-pltcl is earlier than 0:8.4.5-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29636"/>
      <state state_ref="oval:org.mitre.oval:ste:27557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99804" version="1" comment="postgresql is earlier than 0:8.4.5-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:27557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99786" version="1" comment="postgresql-plperl is earlier than 0:8.4.5-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29499"/>
      <state state_ref="oval:org.mitre.oval:ste:27557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99509" version="1" comment="postgresql-docs is earlier than 0:8.4.5-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:27557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99482" version="1" comment="postgresql-libs is earlier than 0:8.4.5-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:27557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99469" version="1" comment="postgresql-server is earlier than 0:8.4.5-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:27557"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98258" version="1" comment="libvirt is earlier than 0:0.8.7-18.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15209"/>
      <state state_ref="oval:org.mitre.oval:ste:27382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98109" version="1" comment="libvirt-python is earlier than 0:0.8.7-18.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15191"/>
      <state state_ref="oval:org.mitre.oval:ste:27382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97911" version="1" comment="libvirt-client is earlier than 0:0.8.7-18.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29031"/>
      <state state_ref="oval:org.mitre.oval:ste:27382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97718" version="1" comment="libvirt-devel is earlier than 0:0.8.7-18.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14880"/>
      <state state_ref="oval:org.mitre.oval:ste:27382"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97760" version="1" comment="sssd-tools is earlier than 0:1.5.1-34.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29289"/>
      <state state_ref="oval:org.mitre.oval:ste:27400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97748" version="1" comment="sssd is earlier than 0:1.5.1-34.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28863"/>
      <state state_ref="oval:org.mitre.oval:ste:27400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97714" version="1" comment="sssd-client is earlier than 0:1.5.1-34.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29292"/>
      <state state_ref="oval:org.mitre.oval:ste:27400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97600" version="1" comment="tomcat6-servlet-2.5-api is earlier than 0:6.0.24-24.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29382"/>
      <state state_ref="oval:org.mitre.oval:ste:27057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97573" version="1" comment="tomcat6-javadoc is earlier than 0:6.0.24-24.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28454"/>
      <state state_ref="oval:org.mitre.oval:ste:27057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97494" version="1" comment="tomcat6-log4j is earlier than 0:6.0.24-24.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30232"/>
      <state state_ref="oval:org.mitre.oval:ste:27057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97452" version="1" comment="tomcat6-lib is earlier than 0:6.0.24-24.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29391"/>
      <state state_ref="oval:org.mitre.oval:ste:27057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97446" version="1" comment="tomcat6-jsp-2.1-api is earlier than 0:6.0.24-24.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29298"/>
      <state state_ref="oval:org.mitre.oval:ste:27057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97423" version="1" comment="tomcat6 is earlier than 0:6.0.24-24.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29276"/>
      <state state_ref="oval:org.mitre.oval:ste:27057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97321" version="1" comment="tomcat6-docs-webapp is earlier than 0:6.0.24-24.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29374"/>
      <state state_ref="oval:org.mitre.oval:ste:27057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97312" version="1" comment="tomcat6-webapps is earlier than 0:6.0.24-24.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29371"/>
      <state state_ref="oval:org.mitre.oval:ste:27057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97291" version="1" comment="tomcat6-admin-webapps is earlier than 0:6.0.24-24.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28477"/>
      <state state_ref="oval:org.mitre.oval:ste:27057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96735" version="1" comment="tomcat6-el-2.1-api is earlier than 0:6.0.24-24.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29264"/>
      <state state_ref="oval:org.mitre.oval:ste:27057"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98681" version="1" comment="sos is earlier than 0:2.2-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29415"/>
      <state state_ref="oval:org.mitre.oval:ste:27273"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97562" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.113.el6_0.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:26728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97184" version="1" comment="qemu-img is earlier than 2:0.12.1.2-2.113.el6_0.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29180"/>
      <state state_ref="oval:org.mitre.oval:ste:26728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96957" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.113.el6_0.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29139"/>
      <state state_ref="oval:org.mitre.oval:ste:26728"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98396" version="1" comment="xulrunner is earlier than 0:1.9.2.20-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27455"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98376" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27455"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98356" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.20-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27489"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98239" version="1" comment="firefox is earlier than 0:3.6.20-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27355"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98011" version="1" comment="firefox is earlier than 0:3.6.20-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27346"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97400" version="1" comment="xulrunner is earlier than 0:1.9.2.20-2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27489"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98267" version="1" comment="ruby-tcltk is earlier than 0:1.8.7.299-7.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14273"/>
      <state state_ref="oval:org.mitre.oval:ste:27298"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98260" version="1" comment="ruby-docs is earlier than 0:1.8.7.299-7.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14446"/>
      <state state_ref="oval:org.mitre.oval:ste:27298"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98206" version="1" comment="ruby-rdoc is earlier than 0:1.8.7.299-7.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14244"/>
      <state state_ref="oval:org.mitre.oval:ste:27298"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98176" version="1" comment="ruby-ri is earlier than 0:1.8.7.299-7.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14461"/>
      <state state_ref="oval:org.mitre.oval:ste:27298"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98010" version="1" comment="ruby-static is earlier than 0:1.8.7.299-7.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28990"/>
      <state state_ref="oval:org.mitre.oval:ste:27298"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97947" version="1" comment="ruby-irb is earlier than 0:1.8.7.299-7.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14777"/>
      <state state_ref="oval:org.mitre.oval:ste:27298"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97909" version="1" comment="ruby is earlier than 0:1.8.7.299-7.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14305"/>
      <state state_ref="oval:org.mitre.oval:ste:27298"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97884" version="1" comment="ruby-libs is earlier than 0:1.8.7.299-7.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14388"/>
      <state state_ref="oval:org.mitre.oval:ste:27298"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97368" version="1" comment="ruby-devel is earlier than 0:1.8.7.299-7.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14187"/>
      <state state_ref="oval:org.mitre.oval:ste:27298"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98883" version="1" comment="pidgin is earlier than 0:2.7.9-3.el6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15157"/>
      <state state_ref="oval:org.mitre.oval:ste:27512"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98809" version="1" comment="finch-devel is earlier than 0:2.7.9-3.el6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15074"/>
      <state state_ref="oval:org.mitre.oval:ste:27512"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98787" version="1" comment="libpurple-perl is earlier than 0:2.7.9-3.el6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15144"/>
      <state state_ref="oval:org.mitre.oval:ste:27512"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98765" version="1" comment="libpurple-tcl is earlier than 0:2.7.9-3.el6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14238"/>
      <state state_ref="oval:org.mitre.oval:ste:27512"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98613" version="1" comment="finch is earlier than 0:2.7.9-3.el6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15156"/>
      <state state_ref="oval:org.mitre.oval:ste:27512"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98431" version="1" comment="pidgin-docs is earlier than 0:2.7.9-3.el6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14724"/>
      <state state_ref="oval:org.mitre.oval:ste:27512"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98279" version="1" comment="libpurple is earlier than 0:2.7.9-3.el6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14700"/>
      <state state_ref="oval:org.mitre.oval:ste:27512"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98148" version="1" comment="libpurple-devel is earlier than 0:2.7.9-3.el6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15112"/>
      <state state_ref="oval:org.mitre.oval:ste:27512"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98020" version="1" comment="pidgin-devel is earlier than 0:2.7.9-3.el6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14642"/>
      <state state_ref="oval:org.mitre.oval:ste:27512"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97926" version="1" comment="pidgin-perl is earlier than 0:2.7.9-3.el6.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14202"/>
      <state state_ref="oval:org.mitre.oval:ste:27512"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97973" version="1" comment="libguestfs-javadoc is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30167"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97950" version="1" comment="ruby-libguestfs is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29776"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97941" version="1" comment="ocaml-libguestfs is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29314"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97897" version="1" comment="libguestfs-mount is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30206"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97823" version="1" comment="perl-Sys-Guestfs is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29983"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97814" version="1" comment="ocaml-libguestfs-devel is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29979"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97799" version="1" comment="libguestfs-devel is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30024"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97726" version="1" comment="python-libguestfs is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30098"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97698" version="1" comment="guestfish is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29869"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97658" version="1" comment="libguestfs-tools-c is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29928"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97629" version="1" comment="libguestfs-java-devel is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30244"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97351" version="1" comment="libguestfs is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30138"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97283" version="1" comment="libguestfs-tools is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29734"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97274" version="1" comment="libguestfs-java is earlier than 1:1.7.17-17.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30086"/>
      <state state_ref="oval:org.mitre.oval:ste:27366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97843" version="1" comment="krb5 is earlier than 0:1.8.2-3.el6_0.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14120"/>
      <state state_ref="oval:org.mitre.oval:ste:27304"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97816" version="1" comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29392"/>
      <state state_ref="oval:org.mitre.oval:ste:27304"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97670" version="1" comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:27304"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97526" version="1" comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:27304"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97493" version="1" comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29451"/>
      <state state_ref="oval:org.mitre.oval:ste:27304"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97126" version="1" comment="krb5-server is earlier than 0:1.8.2-3.el6_0.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:27304"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97040" version="1" comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:27304"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97865" version="1" comment="kdelibs-apidocs is earlier than 6:4.3.4-11.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15138"/>
      <state state_ref="oval:org.mitre.oval:ste:26875"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97795" version="1" comment="kdelibs-common is earlier than 6:4.3.4-11.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30277"/>
      <state state_ref="oval:org.mitre.oval:ste:26875"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97537" version="1" comment="kdelibs is earlier than 6:4.3.4-11.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:26875"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97485" version="1" comment="kdelibs-devel is earlier than 6:4.3.4-11.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:26875"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98312" version="1" comment="fuse-libs is earlier than 0:2.8.3-3.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30239"/>
      <state state_ref="oval:org.mitre.oval:ste:27207"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98291" version="1" comment="fuse-devel is earlier than 0:2.8.3-3.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4385"/>
      <state state_ref="oval:org.mitre.oval:ste:27207"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97701" version="1" comment="fuse is earlier than 0:2.8.3-3.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4411"/>
      <state state_ref="oval:org.mitre.oval:ste:27207"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97656" version="1" comment="wireshark is earlier than 0:1.2.15-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14711"/>
      <state state_ref="oval:org.mitre.oval:ste:27276"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97596" version="1" comment="wireshark-devel is earlier than 0:1.2.15-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30154"/>
      <state state_ref="oval:org.mitre.oval:ste:27276"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97021" version="1" comment="wireshark-gnome is earlier than 0:1.2.15-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14663"/>
      <state state_ref="oval:org.mitre.oval:ste:27276"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97956" version="1" comment="perl-Log-Message is earlier than 1:0.02-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29132"/>
      <state state_ref="oval:org.mitre.oval:ste:26809"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97955" version="1" comment="perl-Test-Harness is earlier than 0:3.17-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29175"/>
      <state state_ref="oval:org.mitre.oval:ste:27197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97949" version="1" comment="perl-ExtUtils-MakeMaker is earlier than 0:6.55-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29536"/>
      <state state_ref="oval:org.mitre.oval:ste:27461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97936" version="1" comment="perl-Log-Message-Simple is earlier than 0:0.04-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29521"/>
      <state state_ref="oval:org.mitre.oval:ste:27150"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97931" version="1" comment="perl-CPAN is earlier than 0:1.9402-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14597"/>
      <state state_ref="oval:org.mitre.oval:ste:27453"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97927" version="1" comment="perl-Object-Accessor is earlier than 1:0.34-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29258"/>
      <state state_ref="oval:org.mitre.oval:ste:27454"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97923" version="1" comment="perl-version is earlier than 3:0.77-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29312"/>
      <state state_ref="oval:org.mitre.oval:ste:27078"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97920" version="1" comment="perl-IO-Compress-Base is earlier than 0:2.020-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29330"/>
      <state state_ref="oval:org.mitre.oval:ste:27319"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97918" version="1" comment="perl-IO-Compress-Zlib is earlier than 0:2.020-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28533"/>
      <state state_ref="oval:org.mitre.oval:ste:27319"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97908" version="1" comment="perl-ExtUtils-CBuilder is earlier than 1:0.27-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29399"/>
      <state state_ref="oval:org.mitre.oval:ste:27427"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97902" version="1" comment="perl-Module-Load is earlier than 1:0.16-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29406"/>
      <state state_ref="oval:org.mitre.oval:ste:27405"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97899" version="1" comment="perl-core is earlier than 0:5.10.1-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29342"/>
      <state state_ref="oval:org.mitre.oval:ste:26778"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97895" version="1" comment="perl-Parse-CPAN-Meta is earlier than 1:1.40-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29541"/>
      <state state_ref="oval:org.mitre.oval:ste:27136"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97889" version="1" comment="perl-Term-UI is earlier than 0:0.20-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29341"/>
      <state state_ref="oval:org.mitre.oval:ste:27141"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97887" version="1" comment="perl-Module-CoreList is earlier than 0:2.18-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29351"/>
      <state state_ref="oval:org.mitre.oval:ste:26463"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97863" version="1" comment="perl-devel is earlier than 4:5.10.1-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29262"/>
      <state state_ref="oval:org.mitre.oval:ste:27363"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97853" version="1" comment="perl-Compress-Raw-Zlib is earlier than 0:2.023-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28825"/>
      <state state_ref="oval:org.mitre.oval:ste:26725"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97851" version="1" comment="perl-Pod-Escapes is earlier than 1:1.04-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29097"/>
      <state state_ref="oval:org.mitre.oval:ste:27287"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97846" version="1" comment="perl-CPANPLUS is earlier than 0:0.88-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29281"/>
      <state state_ref="oval:org.mitre.oval:ste:27446"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97839" version="1" comment="perl-File-Fetch is earlier than 0:0.26-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29401"/>
      <state state_ref="oval:org.mitre.oval:ste:27299"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97812" version="1" comment="perl-ExtUtils-Embed is earlier than 0:1.28-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29397"/>
      <state state_ref="oval:org.mitre.oval:ste:26930"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97810" version="1" comment="perl-Compress-Zlib is earlier than 0:2.020-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29479"/>
      <state state_ref="oval:org.mitre.oval:ste:27319"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97798" version="1" comment="perl-Time-Piece is earlier than 0:1.15-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29412"/>
      <state state_ref="oval:org.mitre.oval:ste:26834"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97794" version="1" comment="perl-Module-Build is earlier than 1:0.3500-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28605"/>
      <state state_ref="oval:org.mitre.oval:ste:27203"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97769" version="1" comment="perl-Digest-SHA is earlier than 1:5.47-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29179"/>
      <state state_ref="oval:org.mitre.oval:ste:26454"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97758" version="1" comment="perl-IPC-Cmd is earlier than 1:0.56-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29378"/>
      <state state_ref="oval:org.mitre.oval:ste:26469"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97739" version="1" comment="perl-Test-Simple is earlier than 0:0.92-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29437"/>
      <state state_ref="oval:org.mitre.oval:ste:26731"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97713" version="1" comment="perl is earlier than 4:5.10.1-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14460"/>
      <state state_ref="oval:org.mitre.oval:ste:27363"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97699" version="1" comment="perl-Package-Constants is earlier than 1:0.02-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29476"/>
      <state state_ref="oval:org.mitre.oval:ste:26809"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97691" version="1" comment="perl-Pod-Simple is earlier than 1:3.13-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29403"/>
      <state state_ref="oval:org.mitre.oval:ste:27341"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97668" version="1" comment="perl-Locale-Maketext-Simple is earlier than 1:0.18-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29426"/>
      <state state_ref="oval:org.mitre.oval:ste:27036"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97655" version="1" comment="perl-IO-Zlib is earlier than 1:1.09-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29321"/>
      <state state_ref="oval:org.mitre.oval:ste:27415"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97636" version="1" comment="perl-Archive-Tar is earlier than 0:1.58-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15210"/>
      <state state_ref="oval:org.mitre.oval:ste:26944"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97599" version="1" comment="perl-parent is earlier than 1:0.221-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29519"/>
      <state state_ref="oval:org.mitre.oval:ste:27262"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97557" version="1" comment="perl-Module-Loaded is earlier than 1:0.02-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29291"/>
      <state state_ref="oval:org.mitre.oval:ste:26809"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97490" version="1" comment="perl-Params-Check is earlier than 1:0.26-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28644"/>
      <state state_ref="oval:org.mitre.oval:ste:27085"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97483" version="1" comment="perl-suidperl is earlier than 4:5.10.1-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13815"/>
      <state state_ref="oval:org.mitre.oval:ste:27363"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97456" version="1" comment="perl-Archive-Extract is earlier than 1:0.38-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28800"/>
      <state state_ref="oval:org.mitre.oval:ste:27302"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97429" version="1" comment="perl-Time-HiRes is earlier than 4:1.9721-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29458"/>
      <state state_ref="oval:org.mitre.oval:ste:27378"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97336" version="1" comment="perl-libs is earlier than 4:5.10.1-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29045"/>
      <state state_ref="oval:org.mitre.oval:ste:27363"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97327" version="1" comment="perl-CGI is earlier than 0:3.51-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14319"/>
      <state state_ref="oval:org.mitre.oval:ste:27291"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97286" version="1" comment="perl-Module-Load-Conditional is earlier than 0:0.30-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29116"/>
      <state state_ref="oval:org.mitre.oval:ste:27375"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97242" version="1" comment="perl-ExtUtils-ParseXS is earlier than 1:2.2003.0-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29307"/>
      <state state_ref="oval:org.mitre.oval:ste:27125"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97090" version="1" comment="perl-Module-Pluggable is earlier than 1:3.90-119.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29466"/>
      <state state_ref="oval:org.mitre.oval:ste:27316"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98075" version="1" comment="avahi-libs is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29841"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98035" version="1" comment="avahi-qt3 is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14742"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98021" version="1" comment="avahi-ui-tools is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29952"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97997" version="1" comment="avahi-glib-devel is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14417"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97986" version="1" comment="avahi-devel is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14981"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97982" version="1" comment="avahi-glib is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14590"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97958" version="1" comment="avahi-ui is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30126"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97934" version="1" comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14977"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97894" version="1" comment="avahi-autoipd is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29947"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97886" version="1" comment="avahi-compat-howl is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14998"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97872" version="1" comment="avahi is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14891"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97845" version="1" comment="avahi-dnsconfd is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29812"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97802" version="1" comment="avahi-gobject-devel is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30087"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97764" version="1" comment="avahi-compat-howl-devel is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14459"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97684" version="1" comment="avahi-tools is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15172"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97638" version="1" comment="avahi-ui-devel is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30235"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97637" version="1" comment="avahi-qt4-devel is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30068"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97631" version="1" comment="avahi-qt4 is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3204"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97532" version="1" comment="avahi-qt3-devel is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14570"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97520" version="1" comment="avahi-compat-libdns_sd is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14856"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97513" version="1" comment="avahi-gobject is earlier than 0:0.6.25-11.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29931"/>
      <state state_ref="oval:org.mitre.oval:ste:27282"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97528" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:26818"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97515" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:26818"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97508" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:26818"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97502" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:26818"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97482" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.24-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:26366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97455" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:26366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97418" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.24-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:26818"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97392" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.24-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:26366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97346" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.24-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:26366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97282" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.24-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:26366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97161" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:26366"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96905" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.24-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:26818"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97503" version="1" comment="flash-plugin is earlier than 0:10.2.152.27-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27160"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137764" version="1" comment="flash-plugin is earlier than 0:10.2.152.27-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:38111"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97416" version="1" comment="vsftpd is earlier than 0:2.2.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14284"/>
      <state state_ref="oval:org.mitre.oval:ste:26299"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137665" version="1" comment="vsftpd-debuginfo is earlier than 0:2.2.2-6.el6_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43166"/>
      <state state_ref="oval:org.mitre.oval:ste:37616"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137483" version="1" comment="vsftpd is earlier than 0:2.0.5-16.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14284"/>
      <state state_ref="oval:org.mitre.oval:ste:38044"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97221" version="1" comment="libuser is earlier than 0:0.56.13-4.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30240"/>
      <state state_ref="oval:org.mitre.oval:ste:26497"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97120" version="1" comment="libuser-python is earlier than 0:0.56.13-4.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30142"/>
      <state state_ref="oval:org.mitre.oval:ste:26497"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97085" version="1" comment="libuser-devel is earlier than 0:0.54.7-2.1.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29973"/>
      <state state_ref="oval:org.mitre.oval:ste:27206"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97036" version="1" comment="libuser-devel is earlier than 0:0.56.13-4.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29973"/>
      <state state_ref="oval:org.mitre.oval:ste:26497"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96455" version="1" comment="libuser is earlier than 0:0.54.7-2.1.el5_5.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30240"/>
      <state state_ref="oval:org.mitre.oval:ste:27206"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99892" version="1" comment="nss-devel is earlier than 0:3.12.8-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:27692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99821" version="1" comment="nss is earlier than 0:3.12.8-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:27692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99772" version="1" comment="nss-softokn is earlier than 0:3.12.8-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29421"/>
      <state state_ref="oval:org.mitre.oval:ste:27692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99731" version="1" comment="nss-util is earlier than 0:3.12.8-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:27692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99729" version="1" comment="nss-tools is earlier than 0:3.12.8-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:27692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99709" version="1" comment="nss-softokn-devel is earlier than 0:3.12.8-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29485"/>
      <state state_ref="oval:org.mitre.oval:ste:27692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99609" version="1" comment="nss-util-devel is earlier than 0:3.12.8-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:27692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99557" version="1" comment="nss-sysinit is earlier than 0:3.12.8-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:27692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99513" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.8-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:27692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99471" version="1" comment="nss-softokn-freebl is earlier than 0:3.12.8-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29159"/>
      <state state_ref="oval:org.mitre.oval:ste:27692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96814" version="1" comment="scsi-target-utils is earlier than 0:1.0.4-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15332"/>
      <state state_ref="oval:org.mitre.oval:ste:26707"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137860" version="1" comment="scsi-target-utils is earlier than 0:1.0.8-0.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15332"/>
      <state state_ref="oval:org.mitre.oval:ste:38235"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137803" version="1" comment="scsi-target-utils-debuginfo is earlier than 0:1.0.4-3.el6_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43368"/>
      <state state_ref="oval:org.mitre.oval:ste:38149"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98151" version="1" comment="libsndfile is earlier than 0:1.0.20-3.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30210"/>
      <state state_ref="oval:org.mitre.oval:ste:27209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97677" version="1" comment="libsndfile-devel is earlier than 0:1.0.20-3.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29527"/>
      <state state_ref="oval:org.mitre.oval:ste:27209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98418" version="1" comment="ecryptfs-utils-python is earlier than 0:82-6.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30225"/>
      <state state_ref="oval:org.mitre.oval:ste:27232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98180" version="1" comment="ecryptfs-utils is earlier than 0:75-5.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15120"/>
      <state state_ref="oval:org.mitre.oval:ste:27390"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98129" version="1" comment="ecryptfs-utils-devel is earlier than 0:75-5.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15215"/>
      <state state_ref="oval:org.mitre.oval:ste:27390"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97689" version="1" comment="ecryptfs-utils-gui is earlier than 0:75-5.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15070"/>
      <state state_ref="oval:org.mitre.oval:ste:27390"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97673" version="1" comment="ecryptfs-utils-devel is earlier than 0:82-6.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15215"/>
      <state state_ref="oval:org.mitre.oval:ste:27232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97518" version="1" comment="ecryptfs-utils is earlier than 0:82-6.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15120"/>
      <state state_ref="oval:org.mitre.oval:ste:27232"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97039" version="1" comment="logwatch is earlier than 0:7.3.6-49.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30246"/>
      <state state_ref="oval:org.mitre.oval:ste:26935"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137653" version="1" comment="logwatch is earlier than 0:7.3-9.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30246"/>
      <state state_ref="oval:org.mitre.oval:ste:37575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97647" version="1" comment="libvirt-python is earlier than 0:0.8.1-27.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15191"/>
      <state state_ref="oval:org.mitre.oval:ste:27045"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97630" version="1" comment="libvirt-client is earlier than 0:0.8.1-27.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29031"/>
      <state state_ref="oval:org.mitre.oval:ste:27045"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97109" version="1" comment="libvirt-devel is earlier than 0:0.8.1-27.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14880"/>
      <state state_ref="oval:org.mitre.oval:ste:27045"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96958" version="1" comment="libvirt is earlier than 0:0.8.1-27.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15209"/>
      <state state_ref="oval:org.mitre.oval:ste:27045"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137859" version="1" comment="libvirt-python is earlier than 0:0.8.2-15.el5_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15191"/>
      <state state_ref="oval:org.mitre.oval:ste:38193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137759" version="1" comment="libvirt-debuginfo is earlier than 0:0.8.1-27.el6_0.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43109"/>
      <state state_ref="oval:org.mitre.oval:ste:37258"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137550" version="1" comment="libvirt-devel is earlier than 0:0.8.2-15.el5_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14880"/>
      <state state_ref="oval:org.mitre.oval:ste:38193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136948" version="1" comment="libvirt is earlier than 0:0.8.2-15.el5_6.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15209"/>
      <state state_ref="oval:org.mitre.oval:ste:38193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97154" version="1" comment="hplip-gui is earlier than 0:3.9.8-33.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29073"/>
      <state state_ref="oval:org.mitre.oval:ste:26863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97133" version="1" comment="hplip-libs is earlier than 0:3.9.8-33.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28847"/>
      <state state_ref="oval:org.mitre.oval:ste:26863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97130" version="1" comment="libsane-hpaio is earlier than 0:3.9.8-33.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14491"/>
      <state state_ref="oval:org.mitre.oval:ste:26863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96882" version="1" comment="hpijs is earlier than 0:3.9.8-33.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14471"/>
      <state state_ref="oval:org.mitre.oval:ste:26863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96578" version="1" comment="hplip-common is earlier than 0:3.9.8-33.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28535"/>
      <state state_ref="oval:org.mitre.oval:ste:26863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96224" version="1" comment="hplip is earlier than 0:3.9.8-33.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3847"/>
      <state state_ref="oval:org.mitre.oval:ste:26863"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137888" version="1" comment="hpijs3 is earlier than 0:3.9.8-11.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28917"/>
      <state state_ref="oval:org.mitre.oval:ste:38160"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137858" version="1" comment="libsane-hpaio is earlier than 0:1.6.7-6.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14491"/>
      <state state_ref="oval:org.mitre.oval:ste:38142"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137659" version="1" comment="hplip3-libs is earlier than 0:3.9.8-11.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29185"/>
      <state state_ref="oval:org.mitre.oval:ste:38160"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137631" version="1" comment="libsane-hpaio3 is earlier than 0:3.9.8-11.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29214"/>
      <state state_ref="oval:org.mitre.oval:ste:38160"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137608" version="1" comment="hplip3-gui is earlier than 0:3.9.8-11.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28796"/>
      <state state_ref="oval:org.mitre.oval:ste:38160"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137565" version="1" comment="hplip-debuginfo is earlier than 0:3.9.8-33.el6_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4426"/>
      <state state_ref="oval:org.mitre.oval:ste:38225"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137564" version="1" comment="hplip is earlier than 0:1.6.7-6.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3847"/>
      <state state_ref="oval:org.mitre.oval:ste:38142"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137308" version="1" comment="hplip3 is earlier than 0:3.9.8-11.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28400"/>
      <state state_ref="oval:org.mitre.oval:ste:38160"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137298" version="1" comment="hpijs is earlier than 0:1.6.7-6.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14471"/>
      <state state_ref="oval:org.mitre.oval:ste:38142"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136965" version="1" comment="hplip3-common is earlier than 0:3.9.8-11.el5_6.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29120"/>
      <state state_ref="oval:org.mitre.oval:ste:38160"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98906" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.209.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:27601"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98881" version="1" comment="qemu-img is earlier than 2:0.12.1.2-2.209.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29180"/>
      <state state_ref="oval:org.mitre.oval:ste:27601"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98344" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.209.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29139"/>
      <state state_ref="oval:org.mitre.oval:ste:27601"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97561" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:26975"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97560" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:27153"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97544" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:26975"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97487" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.12.3-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:27153"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97468" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:27153"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97460" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.12.3-1jpp.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:26975"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97432" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:27153"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97385" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.12.3-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:27153"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97361" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:26975"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97273" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.12.3-1jpp.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:26975"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97272" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.12.3-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:27153"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97268" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:27153"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97207" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.12.3-1jpp.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:26975"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97201" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.12.3-1jpp.2.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:27153"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96815" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.12.3-1jpp.3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:26975"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97804" version="1" comment="postfix-perl-scripts is earlier than 2:2.6.6-2.1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30198"/>
      <state state_ref="oval:org.mitre.oval:ste:27284"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97635" version="1" comment="postfix is earlier than 2:2.6.6-2.1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1466"/>
      <state state_ref="oval:org.mitre.oval:ste:27284"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98655" version="1" comment="postgresql-plperl is earlier than 0:8.4.9-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29499"/>
      <state state_ref="oval:org.mitre.oval:ste:27575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98607" version="1" comment="postgresql-plpython is earlier than 0:8.4.9-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29607"/>
      <state state_ref="oval:org.mitre.oval:ste:27575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98593" version="1" comment="postgresql-docs is earlier than 0:8.1.23-1.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:27605"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98583" version="1" comment="postgresql-devel is earlier than 0:8.1.23-1.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:27605"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98566" version="1" comment="postgresql-pltcl is earlier than 0:8.4.9-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29636"/>
      <state state_ref="oval:org.mitre.oval:ste:27575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98538" version="1" comment="postgresql is earlier than 0:8.4.9-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:27575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98510" version="1" comment="postgresql-docs is earlier than 0:8.4.9-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:27575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98422" version="1" comment="postgresql-pl is earlier than 0:8.1.23-1.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14537"/>
      <state state_ref="oval:org.mitre.oval:ste:27605"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98411" version="1" comment="postgresql-devel is earlier than 0:8.4.9-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:27575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98409" version="1" comment="postgresql-tcl is earlier than 0:8.1.23-1.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14486"/>
      <state state_ref="oval:org.mitre.oval:ste:27605"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98369" version="1" comment="postgresql-libs is earlier than 0:8.1.23-1.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:27605"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98349" version="1" comment="postgresql-libs is earlier than 0:8.4.9-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:27575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98287" version="1" comment="postgresql-contrib is earlier than 0:8.4.9-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:27575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98231" version="1" comment="postgresql-python is earlier than 0:8.1.23-1.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14546"/>
      <state state_ref="oval:org.mitre.oval:ste:27605"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98173" version="1" comment="postgresql-contrib is earlier than 0:8.1.23-1.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:27605"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98172" version="1" comment="postgresql-test is earlier than 0:8.1.23-1.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:27605"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98070" version="1" comment="postgresql is earlier than 0:8.1.23-1.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:27605"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98004" version="1" comment="postgresql-server is earlier than 0:8.4.9-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:27575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97960" version="1" comment="postgresql-server is earlier than 0:8.1.23-1.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:27605"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97945" version="1" comment="postgresql-test is earlier than 0:8.4.9-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:27575"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98090" version="1" comment="systemtap-runtime is earlier than 0:1.4-6.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15292"/>
      <state state_ref="oval:org.mitre.oval:ste:27433"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98031" version="1" comment="systemtap-client is earlier than 0:1.4-6.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15212"/>
      <state state_ref="oval:org.mitre.oval:ste:27433"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97969" version="1" comment="systemtap-grapher is earlier than 0:1.4-6.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30280"/>
      <state state_ref="oval:org.mitre.oval:ste:27433"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97867" version="1" comment="systemtap-sdt-devel is earlier than 0:1.4-6.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14608"/>
      <state state_ref="oval:org.mitre.oval:ste:27433"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97791" version="1" comment="systemtap is earlier than 0:1.4-6.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15026"/>
      <state state_ref="oval:org.mitre.oval:ste:27433"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97770" version="1" comment="systemtap-initscript is earlier than 0:1.4-6.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15362"/>
      <state state_ref="oval:org.mitre.oval:ste:27433"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97747" version="1" comment="systemtap-server is earlier than 0:1.4-6.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14954"/>
      <state state_ref="oval:org.mitre.oval:ste:27433"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97093" version="1" comment="systemtap-testsuite is earlier than 0:1.4-6.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14298"/>
      <state state_ref="oval:org.mitre.oval:ste:27433"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97622" version="1" comment="krb5-libs is earlier than 0:1.8.2-3.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:27271"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97541" version="1" comment="krb5-devel is earlier than 0:1.8.2-3.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:27271"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97500" version="1" comment="krb5-workstation is earlier than 0:1.8.2-3.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:27271"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97448" version="1" comment="krb5-pkinit-openssl is earlier than 0:1.8.2-3.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29392"/>
      <state state_ref="oval:org.mitre.oval:ste:27271"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97404" version="1" comment="krb5-server is earlier than 0:1.8.2-3.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:27271"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96892" version="1" comment="krb5-server-ldap is earlier than 0:1.8.2-3.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29451"/>
      <state state_ref="oval:org.mitre.oval:ste:27271"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96627" version="1" comment="krb5 is earlier than 0:1.8.2-3.el6_0.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14120"/>
      <state state_ref="oval:org.mitre.oval:ste:27271"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98739" version="1" comment="kdelibs3-apidocs is earlier than 0:3.5.10-24.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30313"/>
      <state state_ref="oval:org.mitre.oval:ste:26978"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98646" version="1" comment="kdelibs-devel is earlier than 6:3.5.4-26.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:27451"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98386" version="1" comment="kdelibs3-devel is earlier than 0:3.5.10-24.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29525"/>
      <state state_ref="oval:org.mitre.oval:ste:26978"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98337" version="1" comment="kdelibs-apidocs is earlier than 6:3.5.4-26.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15138"/>
      <state state_ref="oval:org.mitre.oval:ste:27451"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98274" version="1" comment="kdelibs3 is earlier than 0:3.5.10-24.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30319"/>
      <state state_ref="oval:org.mitre.oval:ste:26978"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97744" version="1" comment="kdelibs is earlier than 6:3.5.4-26.el5_7.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:27451"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98116" version="1" comment="thunderbird is earlier than 0:3.1.11-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27144"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98706" version="1" comment="xulrunner is earlier than 0:1.9.2.24-2.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98696" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27562"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98569" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.24-2.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27585"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98533" version="1" comment="firefox is earlier than 0:3.6.24-3.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27234"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98012" version="1" comment="firefox is earlier than 0:3.6.24-3.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27448"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97782" version="1" comment="xulrunner is earlier than 0:1.9.2.24-2.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27562"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98744" version="1" comment="php53-xmlrpc is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29475"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98742" version="1" comment="php-pdo is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98740" version="1" comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98736" version="1" comment="php-snmp is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98718" version="1" comment="php-common is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98716" version="1" comment="php53-snmp is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29427"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98710" version="1" comment="php53-pdo is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29253"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98708" version="1" comment="php-embedded is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98687" version="1" comment="php53-xml is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29235"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98684" version="1" comment="php-odbc is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98661" version="1" comment="php-intl is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98636" version="1" comment="php-tidy is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28881"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98635" version="1" comment="php53-process is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29375"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98625" version="1" comment="php-pgsql is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98618" version="1" comment="php53-gd is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29626"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98562" version="1" comment="php-pspell is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98554" version="1" comment="php-process is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98550" version="1" comment="php53-common is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29562"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98534" version="1" comment="php53-imap is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29568"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98512" version="1" comment="php-recode is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98495" version="1" comment="php-ldap is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98477" version="1" comment="php53-bcmath is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29087"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98467" version="1" comment="php53-mysql is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29022"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98458" version="1" comment="php53-cli is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28902"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98445" version="1" comment="php-zts is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29304"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98444" version="1" comment="php53-odbc is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29337"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98433" version="1" comment="php is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98429" version="1" comment="php53-pgsql is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29505"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98421" version="1" comment="php-bcmath is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98415" version="1" comment="php53-ldap is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29602"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98384" version="1" comment="php-imap is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98358" version="1" comment="php53 is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29556"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98269" version="1" comment="php53-pspell is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29208"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98212" version="1" comment="php53-mbstring is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29008"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98199" version="1" comment="php-enchant is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98177" version="1" comment="php-soap is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98150" version="1" comment="php-mysql is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98124" version="1" comment="php-mbstring is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98099" version="1" comment="php-xml is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98054" version="1" comment="php53-intl is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29195"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98016" version="1" comment="php53-soap is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29455"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97907" version="1" comment="php53-devel is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29547"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97890" version="1" comment="php-cli is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97825" version="1" comment="php53-dba is earlier than 0:5.3.3-1.el5_7.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28950"/>
      <state state_ref="oval:org.mitre.oval:ste:27360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97790" version="1" comment="php-dba is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97767" version="1" comment="php-gd is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97750" version="1" comment="php-devel is earlier than 0:5.3.3-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:27128"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97435" version="1" comment="squid is earlier than 7:3.1.10-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14403"/>
      <state state_ref="oval:org.mitre.oval:ste:27260"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97875" version="1" comment="firefox is earlier than 0:3.6.17-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27093"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97834" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.17-4.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27296"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97757" version="1" comment="xulrunner is earlier than 0:1.9.2.17-4.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27296"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137877" version="1" comment="firefox is earlier than 0:3.6.17-1.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38158"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137848" version="1" comment="firefox is earlier than 0:3.6.17-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137813" version="1" comment="xulrunner is earlier than 0:1.9.2.17-3.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:38255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137795" version="1" comment="xulrunner-debuginfo is earlier than 0:1.9.2.17-4.el6_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43432"/>
      <state state_ref="oval:org.mitre.oval:ste:38125"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137541" version="1" comment="xulrunner is earlier than 0:1.9.2.17-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:37944"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137529" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.17-3.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:37944"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137359" version="1" comment="firefox-debuginfo is earlier than 0:3.6.17-1.el6_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43227"/>
      <state state_ref="oval:org.mitre.oval:ste:37657"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136898" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.17-3.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:38255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99924" version="1" comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3459"/>
      <state state_ref="oval:org.mitre.oval:ste:27656"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99881" version="1" comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3630"/>
      <state state_ref="oval:org.mitre.oval:ste:27656"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100009" version="1" comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15218"/>
      <state state_ref="oval:org.mitre.oval:ste:27656"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97431" version="1" comment="openldap-servers is earlier than 0:2.4.19-15.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14676"/>
      <state state_ref="oval:org.mitre.oval:ste:27012"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97426" version="1" comment="compat-openldap is earlier than 0:2.4.19_2.3.43-15.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14705"/>
      <state state_ref="oval:org.mitre.oval:ste:26888"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97386" version="1" comment="openldap is earlier than 0:2.4.19-15.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14650"/>
      <state state_ref="oval:org.mitre.oval:ste:27012"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97328" version="1" comment="openldap-clients is earlier than 0:2.4.19-15.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13745"/>
      <state state_ref="oval:org.mitre.oval:ste:27012"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97125" version="1" comment="openldap-devel is earlier than 0:2.4.19-15.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14680"/>
      <state state_ref="oval:org.mitre.oval:ste:27012"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96690" version="1" comment="openldap-servers-sql is earlier than 0:2.4.19-15.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14387"/>
      <state state_ref="oval:org.mitre.oval:ste:27012"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99919" version="1" comment="bind-devel is earlier than 32:9.8.2-0.23.rc1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:27897"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100304" version="1" comment="bind-chroot is earlier than 32:9.8.2-0.23.rc1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:27897"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100282" version="1" comment="bind-sdb is earlier than 32:9.8.2-0.23.rc1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:27897"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100262" version="1" comment="bind-libs is earlier than 32:9.8.2-0.23.rc1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:27897"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100083" version="1" comment="bind-utils is earlier than 32:9.8.2-0.23.rc1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:27897"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100041" version="1" comment="bind is earlier than 32:9.8.2-0.23.rc1.el6_5.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:27897"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98428" version="1" comment="libsmbclient-devel is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15335"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98414" version="1" comment="samba is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13931"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98385" version="1" comment="samba-common is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14032"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98359" version="1" comment="libsmbclient is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15389"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98351" version="1" comment="samba-swat is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13707"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98341" version="1" comment="cifs-utils is earlier than 0:4.8.1-2.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30254"/>
      <state state_ref="oval:org.mitre.oval:ste:27121"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98323" version="1" comment="samba-doc is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29416"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98306" version="1" comment="samba-winbind is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29389"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98121" version="1" comment="samba-winbind-krb5-locator is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28660"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98084" version="1" comment="samba-winbind-clients is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29486"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98047" version="1" comment="samba-domainjoin-gui is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97874" version="1" comment="samba-winbind-devel is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29445"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97705" version="1" comment="samba-client is earlier than 0:3.5.6-86.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13861"/>
      <state state_ref="oval:org.mitre.oval:ste:27344"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98145" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:27211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98049" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:27211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98038" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:27391"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98013" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:27391"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97990" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:27391"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97961" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.26-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:27211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97917" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:27211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97900" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.26-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:27211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97807" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.26-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:27391"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97755" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.26-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:27211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97642" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.26-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:27391"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97181" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.26-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:27391"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98044" version="1" comment="bind-sdb is earlier than 32:9.7.3-2.el6_1.P1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:27272"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98025" version="1" comment="bind-chroot is earlier than 32:9.7.3-2.el6_1.P1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:27272"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98017" version="1" comment="bind-utils is earlier than 32:9.7.3-2.el6_1.P1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:27272"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97847" version="1" comment="bind is earlier than 32:9.7.3-2.el6_1.P1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:27272"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97178" version="1" comment="bind-devel is earlier than 32:9.7.3-2.el6_1.P1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:27272"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97153" version="1" comment="bind-libs is earlier than 32:9.7.3-2.el6_1.P1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:27272"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137885" version="1" comment="bind-debuginfo is earlier than 32:9.7.3-2.el6_1.P1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43450"/>
      <state state_ref="oval:org.mitre.oval:ste:37998"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137801" version="1" comment="bind97-devel is earlier than 32:9.7.0-6.P2.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29237"/>
      <state state_ref="oval:org.mitre.oval:ste:37989"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137715" version="1" comment="bind97-libs is earlier than 32:9.7.0-6.P2.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29535"/>
      <state state_ref="oval:org.mitre.oval:ste:37989"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137688" version="1" comment="bind97-chroot is earlier than 32:9.7.0-6.P2.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29448"/>
      <state state_ref="oval:org.mitre.oval:ste:37989"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137605" version="1" comment="bind97 is earlier than 32:9.7.0-6.P2.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28886"/>
      <state state_ref="oval:org.mitre.oval:ste:37989"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136906" version="1" comment="bind97-utils is earlier than 32:9.7.0-6.P2.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28577"/>
      <state state_ref="oval:org.mitre.oval:ste:37989"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100127" version="1" comment="quagga-devel is earlier than 0:0.99.15-5.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14340"/>
      <state state_ref="oval:org.mitre.oval:ste:27533"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100058" version="1" comment="quagga is earlier than 0:0.99.15-5.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14268"/>
      <state state_ref="oval:org.mitre.oval:ste:27533"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100047" version="1" comment="quagga-contrib is earlier than 0:0.99.15-5.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14111"/>
      <state state_ref="oval:org.mitre.oval:ste:27533"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97545" version="1" comment="acroread-plugin is earlier than 0:9.4.2-3.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:27182"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97437" version="1" comment="acroread is earlier than 0:9.4.2-3.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:27182"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97249" version="1" comment="acroread-plugin is earlier than 0:9.4.2-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14489"/>
      <state state_ref="oval:org.mitre.oval:ste:26777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96576" version="1" comment="acroread is earlier than 0:9.4.2-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14858"/>
      <state state_ref="oval:org.mitre.oval:ste:26777"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96945" version="1" comment="kernel-kdump is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96943" version="1" comment="kernel-headers is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96890" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96786" version="1" comment="perf is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96763" version="1" comment="kernel-firmware is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96749" version="1" comment="kernel is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96748" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96562" version="1" comment="kernel-debug is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96254" version="1" comment="kernel-devel is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96226" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96069" version="1" comment="kernel-doc is earlier than 0:2.6.32-71.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27064"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98488" version="1" comment="openswan is earlier than 0:2.6.32-4.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14994"/>
      <state state_ref="oval:org.mitre.oval:ste:26645"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98438" version="1" comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15278"/>
      <state state_ref="oval:org.mitre.oval:ste:26645"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97461" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.36.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:27187"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97445" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.36.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:27187"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97379" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.36.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:27187"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97316" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.36.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:27187"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97143" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.36.b17.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:27187"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137875" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.18.b17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:38211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137857" version="1" comment="java-1.6.0-openjdk-debuginfo is earlier than 1:1.6.0.0-1.36.b17.el6_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42919"/>
      <state state_ref="oval:org.mitre.oval:ste:37773"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137775" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.18.b17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:38211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137751" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.18.b17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:38211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137610" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.18.b17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:38211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137575" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.18.b17.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:38211"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97866" version="1" comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3459"/>
      <state state_ref="oval:org.mitre.oval:ste:27312"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97717" version="1" comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3630"/>
      <state state_ref="oval:org.mitre.oval:ste:27312"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97534" version="1" comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15218"/>
      <state state_ref="oval:org.mitre.oval:ste:27312"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137895" version="1" comment="dhcp-devel is earlier than 12:3.0.5-23.el5_6.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3630"/>
      <state state_ref="oval:org.mitre.oval:ste:38035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137889" version="1" comment="dhcp-debuginfo is earlier than 12:4.1.1-12.P1.el6_0.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3496"/>
      <state state_ref="oval:org.mitre.oval:ste:37474"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137734" version="1" comment="libdhcp4client is earlier than 12:3.0.5-23.el5_6.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30184"/>
      <state state_ref="oval:org.mitre.oval:ste:38035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137712" version="1" comment="dhcp is earlier than 12:3.0.5-23.el5_6.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3459"/>
      <state state_ref="oval:org.mitre.oval:ste:38035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137676" version="1" comment="libdhcp4client-devel is earlier than 12:3.0.5-23.el5_6.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30275"/>
      <state state_ref="oval:org.mitre.oval:ste:38035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137671" version="1" comment="dhclient is earlier than 12:3.0.5-23.el5_6.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15218"/>
      <state state_ref="oval:org.mitre.oval:ste:38035"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113897" version="1" comment="libvirt-devel is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:37751"/>
      <state state_ref="oval:org.mitre.oval:ste:30795"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:113478" version="1" comment="libvirt-lock-sanlock is earlier than 0:0.10.2-29.el6_5.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28971"/>
      <state state_ref="oval:org.mitre.oval:ste:30795"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100278" version="1" comment="thunderbird is earlier than 0:24.3.0-2.el5_10" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27701"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:100038" version="1" comment="thunderbird is earlier than 0:24.3.0-2.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27371"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97811" version="1" comment="thunderbird is earlier than 0:3.1.10-1.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26816"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97535" version="1" comment="subversion-devel is earlier than 0:1.6.11-2.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14983"/>
      <state state_ref="oval:org.mitre.oval:ste:26859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97517" version="1" comment="subversion-perl is earlier than 0:1.6.11-2.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14470"/>
      <state state_ref="oval:org.mitre.oval:ste:26859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97505" version="1" comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14514"/>
      <state state_ref="oval:org.mitre.oval:ste:26859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97501" version="1" comment="subversion is earlier than 0:1.6.11-2.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15298"/>
      <state state_ref="oval:org.mitre.oval:ste:26859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97480" version="1" comment="subversion-ruby is earlier than 0:1.6.11-2.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15192"/>
      <state state_ref="oval:org.mitre.oval:ste:26859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97376" version="1" comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29417"/>
      <state state_ref="oval:org.mitre.oval:ste:26859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97144" version="1" comment="subversion-gnome is earlier than 0:1.6.11-2.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29010"/>
      <state state_ref="oval:org.mitre.oval:ste:26859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96994" version="1" comment="subversion-kde is earlier than 0:1.6.11-2.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29565"/>
      <state state_ref="oval:org.mitre.oval:ste:26859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96988" version="1" comment="subversion-javahl is earlier than 0:1.6.11-2.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15180"/>
      <state state_ref="oval:org.mitre.oval:ste:26859"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97749" version="1" comment="flash-plugin is earlier than 0:10.2.159.1-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27022"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97697" version="1" comment="flash-plugin is earlier than 0:10.2.159.1-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27337"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99891" version="1" comment="kernel-debug is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99874" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99822" version="1" comment="kernel-doc is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99799" version="1" comment="kernel-devel is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99769" version="1" comment="kernel-firmware is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99610" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99597" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99585" version="1" comment="kernel-headers is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99441" version="1" comment="kernel-kdump is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99322" version="1" comment="perf is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:99053" version="1" comment="kernel is earlier than 0:2.6.32-71.7.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27752"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98503" version="1" comment="librsvg2-devel is earlier than 0:2.26.0-5.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30289"/>
      <state state_ref="oval:org.mitre.oval:ste:27329"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98216" version="1" comment="librsvg2 is earlier than 0:2.26.0-5.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30090"/>
      <state state_ref="oval:org.mitre.oval:ste:27329"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97833" version="1" comment="nss-tools is earlier than 0:3.12.8-3.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:26455"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97712" version="1" comment="nss-sysinit is earlier than 0:3.12.8-3.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:26455"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97681" version="1" comment="nss is earlier than 0:3.12.8-3.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:26455"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97578" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.8-3.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:26455"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97411" version="1" comment="nss-devel is earlier than 0:3.12.8-3.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:26455"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137879" version="1" comment="nss is earlier than 0:3.12.8-4.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:38252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137837" version="1" comment="nss-tools is earlier than 0:3.12.8-4.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:38252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137770" version="1" comment="nss-debuginfo is earlier than 0:3.12.8-3.el6_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:42328"/>
      <state state_ref="oval:org.mitre.oval:ste:37848"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137680" version="1" comment="nss-pkcs11-devel is earlier than 0:3.12.8-4.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:38252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136908" version="1" comment="nss-devel is earlier than 0:3.12.8-4.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:38252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97700" version="1" comment="polkit-desktop-policy is earlier than 0:0.96-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29501"/>
      <state state_ref="oval:org.mitre.oval:ste:27383"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97640" version="1" comment="polkit-devel is earlier than 0:0.96-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29498"/>
      <state state_ref="oval:org.mitre.oval:ste:27383"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97601" version="1" comment="polkit-docs is earlier than 0:0.96-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29557"/>
      <state state_ref="oval:org.mitre.oval:ste:27383"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97317" version="1" comment="polkit is earlier than 0:0.96-2.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29347"/>
      <state state_ref="oval:org.mitre.oval:ste:27383"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94940" version="1" comment="libxml2 is earlier than 0:2.7.6-8.el6_3.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:26579"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94892" version="1" comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:26760"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94867" version="1" comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:26579"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94612" version="1" comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:26760"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94495" version="1" comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28876"/>
      <state state_ref="oval:org.mitre.oval:ste:26579"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94428" version="1" comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:26760"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94379" version="1" comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:26579"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94647" version="1" comment="flash-plugin is earlier than 0:11.2.202.251-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:26693"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137431" version="1" comment="flash-plugin is earlier than 0:11.2.202.251-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:37671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98600" version="1" comment="rpm is earlier than 0:4.4.2.3-22.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29926"/>
      <state state_ref="oval:org.mitre.oval:ste:27256"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98577" version="1" comment="popt is earlier than 0:1.10.2.3-22.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30009"/>
      <state state_ref="oval:org.mitre.oval:ste:27198"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98576" version="1" comment="rpm-libs is earlier than 0:4.4.2.3-22.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29957"/>
      <state state_ref="oval:org.mitre.oval:ste:27256"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98544" version="1" comment="rpm is earlier than 0:4.8.0-16.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29926"/>
      <state state_ref="oval:org.mitre.oval:ste:27496"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98501" version="1" comment="rpm-libs is earlier than 0:4.8.0-16.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29957"/>
      <state state_ref="oval:org.mitre.oval:ste:27496"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98499" version="1" comment="rpm-build is earlier than 0:4.4.2.3-22.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29890"/>
      <state state_ref="oval:org.mitre.oval:ste:27256"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98481" version="1" comment="rpm-apidocs is earlier than 0:4.4.2.3-22.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29915"/>
      <state state_ref="oval:org.mitre.oval:ste:27256"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98449" version="1" comment="rpm-cron is earlier than 0:4.8.0-16.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29996"/>
      <state state_ref="oval:org.mitre.oval:ste:27496"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98400" version="1" comment="rpm-apidocs is earlier than 0:4.8.0-16.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29915"/>
      <state state_ref="oval:org.mitre.oval:ste:27496"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98377" version="1" comment="rpm-devel is earlier than 0:4.8.0-16.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30331"/>
      <state state_ref="oval:org.mitre.oval:ste:27496"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98357" version="1" comment="rpm-devel is earlier than 0:4.4.2.3-22.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30331"/>
      <state state_ref="oval:org.mitre.oval:ste:27256"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98316" version="1" comment="rpm-python is earlier than 0:4.4.2.3-22.el5_7.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30032"/>
      <state state_ref="oval:org.mitre.oval:ste:27256"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98154" version="1" comment="rpm-python is earlier than 0:4.8.0-16.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30032"/>
      <state state_ref="oval:org.mitre.oval:ste:27496"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97971" version="1" comment="rpm-build is earlier than 0:4.8.0-16.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29890"/>
      <state state_ref="oval:org.mitre.oval:ste:27496"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98651" version="1" comment="openssl-static is earlier than 0:1.0.0-10.el6_1.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:27314"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98586" version="1" comment="openssl is earlier than 0:1.0.0-10.el6_1.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:27314"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98389" version="1" comment="openssl-perl is earlier than 0:1.0.0-10.el6_1.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:27314"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98304" version="1" comment="openssl-devel is earlier than 0:1.0.0-10.el6_1.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:27314"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97981" version="1" comment="kernel-headers is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97970" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97925" version="1" comment="kernel is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97912" version="1" comment="perf is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97896" version="1" comment="kernel-firmware is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97893" version="1" comment="kernel-debug is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97892" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97779" version="1" comment="kernel-doc is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97772" version="1" comment="kernel-kdump is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97735" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97612" version="1" comment="kernel-devel is earlier than 0:2.6.32-131.0.15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27190"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94908" version="1" comment="mysql-libs is earlier than 0:5.1.66-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28723"/>
      <state state_ref="oval:org.mitre.oval:ste:26526"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94903" version="1" comment="mysql-embedded-devel is earlier than 0:5.1.66-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28807"/>
      <state state_ref="oval:org.mitre.oval:ste:26526"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94813" version="1" comment="mysql-bench is earlier than 0:5.1.66-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14400"/>
      <state state_ref="oval:org.mitre.oval:ste:26526"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94794" version="1" comment="mysql-test is earlier than 0:5.1.66-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14941"/>
      <state state_ref="oval:org.mitre.oval:ste:26526"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94483" version="1" comment="mysql-server is earlier than 0:5.1.66-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14342"/>
      <state state_ref="oval:org.mitre.oval:ste:26526"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94395" version="1" comment="mysql-embedded is earlier than 0:5.1.66-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28870"/>
      <state state_ref="oval:org.mitre.oval:ste:26526"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94388" version="1" comment="mysql is earlier than 0:5.1.66-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14355"/>
      <state state_ref="oval:org.mitre.oval:ste:26526"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93930" version="1" comment="mysql-devel is earlier than 0:5.1.66-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14481"/>
      <state state_ref="oval:org.mitre.oval:ste:26526"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98774" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98758" version="1" comment="kernel is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98753" version="1" comment="kernel-firmware is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98749" version="1" comment="kernel-kdump is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98612" version="1" comment="perf is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98610" version="1" comment="kernel-headers is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98511" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98496" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98457" version="1" comment="kernel-debug is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98378" version="1" comment="kernel-doc is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98193" version="1" comment="kernel-devel is earlier than 0:2.6.32-131.21.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98990" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.51-2.4.4.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:27335"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98951" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.51-2.4.4.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:27335"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98892" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.51-2.4.4.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:27335"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98705" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.51-2.4.4.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:27335"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98599" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.51-2.4.4.1.el6_5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:27335"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98796" version="1" comment="jasper-devel is earlier than 0:1.900.1-15.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30186"/>
      <state state_ref="oval:org.mitre.oval:ste:27358"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98766" version="1" comment="jasper-utils is earlier than 0:1.900.1-15.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30190"/>
      <state state_ref="oval:org.mitre.oval:ste:27358"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98671" version="1" comment="jasper-libs is earlier than 0:1.900.1-15.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29982"/>
      <state state_ref="oval:org.mitre.oval:ste:27358"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98372" version="1" comment="jasper is earlier than 0:1.900.1-15.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29898"/>
      <state state_ref="oval:org.mitre.oval:ste:27358"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94887" version="1" comment="gegl-devel is earlier than 0:0.1.2-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29387"/>
      <state state_ref="oval:org.mitre.oval:ste:26632"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94672" version="1" comment="gegl is earlier than 0:0.1.2-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29863"/>
      <state state_ref="oval:org.mitre.oval:ste:26632"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98483" version="1" comment="flash-plugin is earlier than 0:10.3.183.11-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27000"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98326" version="1" comment="flash-plugin is earlier than 0:10.3.183.11-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:27588"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94939" version="1" comment="thunderbird is earlier than 0:10.0.11-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:25915"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94901" version="1" comment="thunderbird is earlier than 0:10.0.11-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26720"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94864" version="1" comment="thunderbird is earlier than 0:10.0.11-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26287"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94413" version="1" comment="thunderbird is earlier than 0:10.0.11-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26330"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97569" version="1" comment="libtiff-static is earlier than 0:3.9.4-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30004"/>
      <state state_ref="oval:org.mitre.oval:ste:26943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97364" version="1" comment="libtiff-devel is earlier than 0:3.9.4-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:26943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96582" version="1" comment="libtiff is earlier than 0:3.9.4-1.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:26943"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137522" version="1" comment="libtiff-debuginfo is earlier than 0:3.9.4-1.el6_0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43296"/>
      <state state_ref="oval:org.mitre.oval:ste:38228"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137374" version="1" comment="libtiff-devel is earlier than 0:3.8.2-7.el5_6.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:38016"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137251" version="1" comment="libtiff is earlier than 0:3.8.2-7.el5_6.6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:38016"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97978" version="1" comment="python-libs is earlier than 0:2.6.6-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29635"/>
      <state state_ref="oval:org.mitre.oval:ste:27307"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97975" version="1" comment="python-devel is earlier than 0:2.6.6-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14166"/>
      <state state_ref="oval:org.mitre.oval:ste:27307"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97957" version="1" comment="python-test is earlier than 0:2.6.6-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29582"/>
      <state state_ref="oval:org.mitre.oval:ste:27307"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97952" version="1" comment="python-tools is earlier than 0:2.6.6-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14208"/>
      <state state_ref="oval:org.mitre.oval:ste:27307"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97840" version="1" comment="python-docs is earlier than 0:2.6.6-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14500"/>
      <state state_ref="oval:org.mitre.oval:ste:27364"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97773" version="1" comment="tkinter is earlier than 0:2.6.6-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14092"/>
      <state state_ref="oval:org.mitre.oval:ste:27307"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97659" version="1" comment="python is earlier than 0:2.6.6-20.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14556"/>
      <state state_ref="oval:org.mitre.oval:ste:27307"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97349" version="1" comment="openoffice.org-langpack-hr_HR is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14336"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97314" version="1" comment="openoffice.org-langpack-hu_HU is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14694"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97313" version="1" comment="openoffice.org-langpack-pt_BR is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14822"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97307" version="1" comment="openoffice.org-langpack-he_IL is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14442"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97304" version="1" comment="openoffice.org-langpack-tn_ZA is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14432"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97302" version="1" comment="autocorr-bg is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29905"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97301" version="1" comment="openoffice.org-langpack-ro is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29352"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97295" version="1" comment="openoffice.org-langpack-el_GR is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14359"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97293" version="1" comment="openoffice.org-langpack-pt_PT is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14571"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97292" version="1" comment="autocorr-vi is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29710"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97287" version="1" comment="autocorr-sl is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29963"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97281" version="1" comment="openoffice.org-langpack-ga_IE is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14635"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97275" version="1" comment="openoffice.org-langpack-te_IN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14832"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97267" version="1" comment="openoffice.org-langpack-nl is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14909"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97263" version="1" comment="openoffice.org-langpack-xh_ZA is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14738"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97262" version="1" comment="openoffice.org-writer-core is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30046"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97252" version="1" comment="openoffice.org-langpack-ar is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14872"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97248" version="1" comment="autocorr-eu is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29677"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97246" version="1" comment="autocorr-it is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30252"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97245" version="1" comment="openoffice.org-langpack-as_IN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14576"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97239" version="1" comment="openoffice.org-opensymbol-fonts is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29944"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97236" version="1" comment="openoffice.org-langpack-mr_IN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14855"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97233" version="1" comment="autocorr-ru is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30139"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97232" version="1" comment="openoffice.org-langpack-sr is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30247"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97230" version="1" comment="broffice.org-brand is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30157"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97228" version="1" comment="openoffice.org-langpack-pl_PL is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14767"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97226" version="1" comment="openoffice.org-rhino is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29811"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97225" version="1" comment="openoffice.org-testtools is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14135"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97223" version="1" comment="openoffice.org-calc is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14623"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97216" version="1" comment="openoffice.org-langpack-nb_NO is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14807"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97208" version="1" comment="openoffice.org-report-builder is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30113"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97206" version="1" comment="openoffice.org-pyuno is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14806"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97203" version="1" comment="openoffice.org-langpack-th_TH is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14732"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97195" version="1" comment="openoffice.org-langpack-ss_ZA is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14728"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97194" version="1" comment="openoffice.org-langpack-zh_CN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14839"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97193" version="1" comment="openoffice.org-langpack-ms_MY is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14787"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97191" version="1" comment="autocorr-pl is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30243"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97190" version="1" comment="broffice.org-calc is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29850"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97189" version="1" comment="openoffice.org-xsltfilter is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14530"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97188" version="1" comment="openoffice.org-langpack-eu_ES is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14813"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97187" version="1" comment="openoffice.org-langpack-hi_IN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14717"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97185" version="1" comment="openoffice.org-draw is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14828"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97182" version="1" comment="autocorr-lb is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30037"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97179" version="1" comment="openoffice.org-langpack-ko_KR is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14190"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97175" version="1" comment="openoffice.org-langpack-dz is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30220"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97174" version="1" comment="openoffice.org-langpack-uk is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29280"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97171" version="1" comment="openoffice.org-sdk-doc is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14165"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97168" version="1" comment="autocorr-fa is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30054"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97165" version="1" comment="openoffice.org-langpack-zh_TW is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14392"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97152" version="1" comment="openoffice.org-math-core is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30016"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97151" version="1" comment="openoffice.org-langpack-fr is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14772"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97150" version="1" comment="openoffice.org-langpack-ru is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14766"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97145" version="1" comment="autocorr-lt is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30162"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97132" version="1" comment="autocorr-hu is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30059"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97131" version="1" comment="openoffice.org-langpack-st_ZA is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14851"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97129" version="1" comment="broffice.org-base is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30044"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97123" version="1" comment="openoffice.org-langpack-or_IN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14588"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97119" version="1" comment="openoffice.org-base-core is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30195"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97118" version="1" comment="autocorr-tr is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29892"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97117" version="1" comment="autocorr-da is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30007"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97113" version="1" comment="openoffice.org-wiki-publisher is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29792"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97110" version="1" comment="openoffice.org-langpack-ml_IN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14257"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97108" version="1" comment="openoffice.org-core is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14450"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97107" version="1" comment="openoffice.org-langpack-cy_GB is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14501"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97106" version="1" comment="openoffice.org-langpack-ta_IN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14637"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97102" version="1" comment="autocorr-en is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29653"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97100" version="1" comment="openoffice.org-langpack-da_DK is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14748"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97096" version="1" comment="autocorr-de is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30208"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97094" version="1" comment="openoffice.org-brand is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30081"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97091" version="1" comment="openoffice.org-langpack-zu_ZA is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14562"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97089" version="1" comment="openoffice.org-draw-core is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30039"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97077" version="1" comment="openoffice.org-langpack-gu_IN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14269"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97067" version="1" comment="openoffice.org-langpack-kn_IN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14714"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97064" version="1" comment="openoffice.org-langpack-sk_SK is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14266"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97055" version="1" comment="openoffice.org-langpack-fi_FI is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14625"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97052" version="1" comment="openoffice.org-calc-core is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30242"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97051" version="1" comment="autocorr-es is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30030"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97048" version="1" comment="openoffice.org-langpack-cs_CZ is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14865"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97046" version="1" comment="openoffice.org-math is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14557"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97044" version="1" comment="broffice.org-writer is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29414"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97033" version="1" comment="openoffice.org-ogltrans is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29462"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97024" version="1" comment="openoffice.org-langpack-af_ZA is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14506"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97013" version="1" comment="openoffice.org-langpack-ve_ZA is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14900"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97007" version="1" comment="openoffice.org-graphicfilter is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14526"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97005" version="1" comment="broffice.org-draw is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30204"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97001" version="1" comment="broffice.org-math is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30071"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96991" version="1" comment="openoffice.org-langpack-gl_ES is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14792"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96987" version="1" comment="autocorr-mn is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29916"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96977" version="1" comment="autocorr-nl is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30095"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96974" version="1" comment="openoffice.org-langpack-it is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14812"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96972" version="1" comment="openoffice.org-base is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14548"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96970" version="1" comment="openoffice.org-langpack-es is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14604"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96960" version="1" comment="openoffice.org-langpack-ur is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14671"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96938" version="1" comment="autocorr-sv is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29750"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96937" version="1" comment="openoffice.org-headless is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14864"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96936" version="1" comment="autocorr-ja is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30255"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96929" version="1" comment="openoffice.org-langpack-sl_SI is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14869"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96907" version="1" comment="openoffice.org-bsh is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30026"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96880" version="1" comment="openoffice.org-langpack-ts_ZA is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14056"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96871" version="1" comment="openoffice.org-pdfimport is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30143"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96870" version="1" comment="openoffice.org-ure is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14811"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96864" version="1" comment="openoffice.org is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13461"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96861" version="1" comment="openoffice.org-langpack-bg_BG is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14589"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96848" version="1" comment="openoffice.org-langpack-nso_ZA is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13974"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96843" version="1" comment="openoffice.org-langpack-tr_TR is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14886"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96823" version="1" comment="openoffice.org-javafilter is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14566"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96817" version="1" comment="openoffice.org-impress-core is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29333"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96812" version="1" comment="openoffice.org-emailmerge is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14522"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96808" version="1" comment="openoffice.org-presenter-screen is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29967"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96798" version="1" comment="autocorr-fr is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30101"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96795" version="1" comment="openoffice.org-presentation-minimizer is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30111"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96779" version="1" comment="openoffice.org-langpack-et_EE is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14280"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96724" version="1" comment="openoffice.org-langpack-pa is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29797"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96687" version="1" comment="autocorr-af is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30010"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96660" version="1" comment="autocorr-pt is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30135"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96656" version="1" comment="autocorr-cs is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30182"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96639" version="1" comment="openoffice.org-langpack-sv is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14529"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96620" version="1" comment="openoffice.org-langpack-de is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14539"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96618" version="1" comment="openoffice.org-langpack-en is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30061"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96586" version="1" comment="openoffice.org-langpack-nn_NO is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14779"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96565" version="1" comment="autocorr-zh is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30170"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96551" version="1" comment="openoffice.org-langpack-lt_LT is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13921"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96538" version="1" comment="autocorr-ko is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30073"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96534" version="1" comment="broffice.org-impress is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29972"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96449" version="1" comment="openoffice.org-sdk is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14664"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96446" version="1" comment="openoffice.org-langpack-ca_ES is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14778"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96425" version="1" comment="autocorr-fi is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30034"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96412" version="1" comment="openoffice.org-langpack-mai_IN is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30110"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96392" version="1" comment="autocorr-sk is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30092"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96350" version="1" comment="openoffice.org-langpack-nr_ZA is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14651"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96338" version="1" comment="openoffice.org-langpack-bn is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14706"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96330" version="1" comment="openoffice.org-impress is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14707"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96326" version="1" comment="openoffice.org-langpack-ja_JP is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14155"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96314" version="1" comment="openoffice.org-writer is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14758"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96291" version="1" comment="autocorr-ga is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30233"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96249" version="1" comment="openoffice.org-devel is earlier than 1:3.2.1-19.6.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30200"/>
      <state state_ref="oval:org.mitre.oval:ste:26252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97586" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:26747"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97570" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.9.1-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:27135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97566" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:26747"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97522" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:27135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97496" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.9.1-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:27135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97474" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:26747"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97465" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.9.1-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:27135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97412" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.9.1-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:27135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97331" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:27135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97271" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:27135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97227" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.9.1-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:26747"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97177" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.9.1-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:26747"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97115" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:27135"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96949" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.9.1-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:26747"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96645" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.9.1-1jpp.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:26747"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98480" version="1" comment="thunderbird is earlier than 0:3.1.16-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26948"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98120" version="1" comment="cyrus-imapd-utils is earlier than 0:2.3.16-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14555"/>
      <state state_ref="oval:org.mitre.oval:ste:26624"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98096" version="1" comment="cyrus-imapd-devel is earlier than 0:2.3.16-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3584"/>
      <state state_ref="oval:org.mitre.oval:ste:26624"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98076" version="1" comment="cyrus-imapd is earlier than 0:2.3.16-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3854"/>
      <state state_ref="oval:org.mitre.oval:ste:26624"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137863" version="1" comment="cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_6.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14555"/>
      <state state_ref="oval:org.mitre.oval:ste:38218"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137794" version="1" comment="cyrus-imapd is earlier than 0:2.3.7-7.el5_6.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3854"/>
      <state state_ref="oval:org.mitre.oval:ste:38218"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137763" version="1" comment="cyrus-imapd-debuginfo is earlier than 0:2.3.16-6.el6_1.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3628"/>
      <state state_ref="oval:org.mitre.oval:ste:38241"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137725" version="1" comment="cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_6.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14774"/>
      <state state_ref="oval:org.mitre.oval:ste:38218"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137312" version="1" comment="cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_6.4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3584"/>
      <state state_ref="oval:org.mitre.oval:ste:38218"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94843" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:26488"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94795" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:26488"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94732" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:26488"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94718" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:26488"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94711" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:26488"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94316" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:26488"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94301" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.15.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:26488"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137914" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:38132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137815" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:38132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137765" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:38132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137560" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:38132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137245" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:38132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137182" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:38132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136920" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:38132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136914" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.15.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:38132"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98346" version="1" comment="systemtap-server is earlier than 0:1.4-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14954"/>
      <state state_ref="oval:org.mitre.oval:ste:27238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98294" version="1" comment="systemtap-grapher is earlier than 0:1.4-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30280"/>
      <state state_ref="oval:org.mitre.oval:ste:27238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98233" version="1" comment="systemtap-client is earlier than 0:1.4-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15212"/>
      <state state_ref="oval:org.mitre.oval:ste:27238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98192" version="1" comment="systemtap is earlier than 0:1.4-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15026"/>
      <state state_ref="oval:org.mitre.oval:ste:27238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98131" version="1" comment="systemtap-initscript is earlier than 0:1.4-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15362"/>
      <state state_ref="oval:org.mitre.oval:ste:27238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98072" version="1" comment="systemtap-testsuite is earlier than 0:1.4-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14298"/>
      <state state_ref="oval:org.mitre.oval:ste:27238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97679" version="1" comment="systemtap-sdt-devel is earlier than 0:1.4-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14608"/>
      <state state_ref="oval:org.mitre.oval:ste:27238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97360" version="1" comment="systemtap-runtime is earlier than 0:1.4-6.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15292"/>
      <state state_ref="oval:org.mitre.oval:ste:27238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94729" version="1" comment="java-1.7.0-ibm-src is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29064"/>
      <state state_ref="oval:org.mitre.oval:ste:26285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94725" version="1" comment="java-1.7.0-ibm-jdbc is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29107"/>
      <state state_ref="oval:org.mitre.oval:ste:26285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94723" version="1" comment="java-1.7.0-ibm-demo is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28974"/>
      <state state_ref="oval:org.mitre.oval:ste:26285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94698" version="1" comment="java-1.7.0-ibm is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28520"/>
      <state state_ref="oval:org.mitre.oval:ste:26285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94350" version="1" comment="java-1.7.0-ibm-devel is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29376"/>
      <state state_ref="oval:org.mitre.oval:ste:26285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94067" version="1" comment="java-1.7.0-ibm-plugin is earlier than 1:1.7.0.2.0-1jpp.3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29364"/>
      <state state_ref="oval:org.mitre.oval:ste:26285"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94529" version="1" comment="ghostscript-gtk is earlier than 0:8.70-14.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14614"/>
      <state state_ref="oval:org.mitre.oval:ste:26176"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94516" version="1" comment="ghostscript-doc is earlier than 0:8.70-14.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28978"/>
      <state state_ref="oval:org.mitre.oval:ste:26176"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94481" version="1" comment="ghostscript-devel is earlier than 0:8.70-14.el5_8.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14524"/>
      <state state_ref="oval:org.mitre.oval:ste:26607"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94323" version="1" comment="ghostscript-gtk is earlier than 0:8.70-14.el5_8.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14614"/>
      <state state_ref="oval:org.mitre.oval:ste:26607"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94158" version="1" comment="ghostscript is earlier than 0:8.70-14.el5_8.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14541"/>
      <state state_ref="oval:org.mitre.oval:ste:26607"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93913" version="1" comment="ghostscript is earlier than 0:8.70-14.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14541"/>
      <state state_ref="oval:org.mitre.oval:ste:26176"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93565" version="1" comment="ghostscript-devel is earlier than 0:8.70-14.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14524"/>
      <state state_ref="oval:org.mitre.oval:ste:26176"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94429" version="1" comment="gimp-libs is earlier than 2:2.6.9-4.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14790"/>
      <state state_ref="oval:org.mitre.oval:ste:26506"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94327" version="1" comment="gimp is earlier than 2:2.6.9-4.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:5002"/>
      <state state_ref="oval:org.mitre.oval:ste:26506"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94182" version="1" comment="gimp-devel-tools is earlier than 2:2.6.9-4.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29218"/>
      <state state_ref="oval:org.mitre.oval:ste:26506"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94110" version="1" comment="gimp-devel is earlier than 2:2.6.9-4.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4711"/>
      <state state_ref="oval:org.mitre.oval:ste:26506"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93814" version="1" comment="gimp-help-browser is earlier than 2:2.6.9-4.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29490"/>
      <state state_ref="oval:org.mitre.oval:ste:26506"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97983" version="1" comment="eclipse-emf-xsd-sdk is earlier than 0:2.6.0-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30262"/>
      <state state_ref="oval:org.mitre.oval:ste:26854"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97980" version="1" comment="eclipse-valgrind is earlier than 0:0.6.1-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30271"/>
      <state state_ref="oval:org.mitre.oval:ste:27033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97974" version="1" comment="eclipse-mylyn-trac is earlier than 0:3.4.2-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29429"/>
      <state state_ref="oval:org.mitre.oval:ste:26877"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97966" version="1" comment="eclipse-mylyn-java is earlier than 0:3.4.2-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30125"/>
      <state state_ref="oval:org.mitre.oval:ste:26877"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97959" version="1" comment="eclipse-mylyn-webtasks is earlier than 0:3.4.2-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29577"/>
      <state state_ref="oval:org.mitre.oval:ste:26877"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97951" version="1" comment="eclipse-changelog is earlier than 1:2.7.0-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29821"/>
      <state state_ref="oval:org.mitre.oval:ste:26772"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97944" version="1" comment="eclipse-callgraph is earlier than 0:0.6.1-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30064"/>
      <state state_ref="oval:org.mitre.oval:ste:27033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97940" version="1" comment="eclipse-swt is earlier than 1:3.6.1-6.13.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29761"/>
      <state state_ref="oval:org.mitre.oval:ste:26942"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97932" version="1" comment="jetty-eclipse is earlier than 0:6.1.24-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30257"/>
      <state state_ref="oval:org.mitre.oval:ste:27278"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97922" version="1" comment="eclipse-emf-xsd is earlier than 0:2.6.0-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30117"/>
      <state state_ref="oval:org.mitre.oval:ste:26854"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97906" version="1" comment="eclipse-emf-examples is earlier than 0:2.6.0-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29700"/>
      <state state_ref="oval:org.mitre.oval:ste:26854"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97905" version="1" comment="eclipse-cdt-parsers is earlier than 1:7.0.1-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29674"/>
      <state state_ref="oval:org.mitre.oval:ste:27417"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97883" version="1" comment="eclipse-oprofile is earlier than 0:0.6.1-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29937"/>
      <state state_ref="oval:org.mitre.oval:ste:27033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97878" version="1" comment="eclipse-mylyn is earlier than 0:3.4.2-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30238"/>
      <state state_ref="oval:org.mitre.oval:ste:26877"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97877" version="1" comment="icu4j-javadoc is earlier than 1:4.2.1-5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29736"/>
      <state state_ref="oval:org.mitre.oval:ste:26475"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97876" version="1" comment="eclipse-mylyn-cdt is earlier than 0:3.4.2-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30217"/>
      <state state_ref="oval:org.mitre.oval:ste:26877"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97860" version="1" comment="eclipse-gef-sdk is earlier than 0:3.6.1-3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29847"/>
      <state state_ref="oval:org.mitre.oval:ste:26988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97800" version="1" comment="eclipse-rse is earlier than 0:3.2-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30207"/>
      <state state_ref="oval:org.mitre.oval:ste:27351"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97768" version="1" comment="eclipse-cdt-sdk is earlier than 1:7.0.1-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29447"/>
      <state state_ref="oval:org.mitre.oval:ste:27417"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97754" version="1" comment="objectweb-asm is earlier than 0:3.2-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30230"/>
      <state state_ref="oval:org.mitre.oval:ste:27313"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97733" version="1" comment="eclipse is earlier than 1:3.6.1-6.13.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3804"/>
      <state state_ref="oval:org.mitre.oval:ste:26942"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97729" version="1" comment="objectweb-asm-javadoc is earlier than 0:3.2-2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29923"/>
      <state state_ref="oval:org.mitre.oval:ste:27313"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97723" version="1" comment="eclipse-cdt is earlier than 1:7.0.1-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3965"/>
      <state state_ref="oval:org.mitre.oval:ste:27417"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97711" version="1" comment="eclipse-emf is earlier than 0:2.6.0-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29715"/>
      <state state_ref="oval:org.mitre.oval:ste:26854"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97663" version="1" comment="icu4j is earlier than 1:4.2.1-5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29948"/>
      <state state_ref="oval:org.mitre.oval:ste:26475"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97662" version="1" comment="sat4j is earlier than 0:2.2.0-4.0.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29882"/>
      <state state_ref="oval:org.mitre.oval:ste:27289"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97661" version="1" comment="eclipse-rcp is earlier than 1:3.6.1-6.13.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30253"/>
      <state state_ref="oval:org.mitre.oval:ste:26942"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97628" version="1" comment="eclipse-mylyn-wikitext is earlier than 0:3.4.2-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29719"/>
      <state state_ref="oval:org.mitre.oval:ste:26877"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97620" version="1" comment="eclipse-birt is earlier than 0:2.6.0-1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30146"/>
      <state state_ref="oval:org.mitre.oval:ste:27418"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97614" version="1" comment="eclipse-gef is earlier than 0:3.6.1-3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30012"/>
      <state state_ref="oval:org.mitre.oval:ste:26988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97606" version="1" comment="eclipse-platform is earlier than 1:3.6.1-6.13.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4267"/>
      <state state_ref="oval:org.mitre.oval:ste:26942"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97603" version="1" comment="eclipse-emf-sdk is earlier than 0:2.6.0-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29993"/>
      <state state_ref="oval:org.mitre.oval:ste:26854"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97491" version="1" comment="eclipse-mylyn-pde is earlier than 0:3.4.2-9.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30191"/>
      <state state_ref="oval:org.mitre.oval:ste:26877"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97484" version="1" comment="icu4j-eclipse is earlier than 1:4.2.1-5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30270"/>
      <state state_ref="oval:org.mitre.oval:ste:26475"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97458" version="1" comment="eclipse-jdt is earlier than 1:3.6.1-6.13.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4277"/>
      <state state_ref="oval:org.mitre.oval:ste:26942"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97442" version="1" comment="eclipse-pde is earlier than 1:3.6.1-6.13.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4224"/>
      <state state_ref="oval:org.mitre.oval:ste:26942"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97350" version="1" comment="eclipse-dtp is earlier than 0:1.8.1-1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30181"/>
      <state state_ref="oval:org.mitre.oval:ste:27255"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97318" version="1" comment="eclipse-gef-examples is earlier than 0:3.6.1-3.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30123"/>
      <state state_ref="oval:org.mitre.oval:ste:26988"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97202" version="1" comment="eclipse-linuxprofilingframework is earlier than 0:0.6.1-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30263"/>
      <state state_ref="oval:org.mitre.oval:ste:27033"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97539" version="1" comment="kernel-firmware is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97524" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97481" version="1" comment="kernel-devel is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97470" version="1" comment="kernel-debug is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97440" version="1" comment="perf is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97414" version="1" comment="kernel-headers is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97393" version="1" comment="kernel is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97389" version="1" comment="kernel-doc is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97377" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97235" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96934" version="1" comment="kernel-kdump is earlier than 0:2.6.32-71.18.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27185"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94178" version="1" comment="openldap-servers-sql is earlier than 0:2.4.23-26.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14387"/>
      <state state_ref="oval:org.mitre.oval:ste:26280"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94036" version="1" comment="openldap is earlier than 0:2.4.23-26.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14650"/>
      <state state_ref="oval:org.mitre.oval:ste:26280"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93877" version="1" comment="openldap-devel is earlier than 0:2.4.23-26.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14680"/>
      <state state_ref="oval:org.mitre.oval:ste:26280"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93855" version="1" comment="openldap-clients is earlier than 0:2.4.23-26.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13745"/>
      <state state_ref="oval:org.mitre.oval:ste:26280"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93456" version="1" comment="openldap-servers is earlier than 0:2.4.23-26.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14676"/>
      <state state_ref="oval:org.mitre.oval:ste:26280"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98152" version="1" comment="foomatic is earlier than 0:4.0.4-1.el6_1.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30318"/>
      <state state_ref="oval:org.mitre.oval:ste:27306"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93757" version="1" comment="flash-plugin is earlier than 0:11.2.202.243-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:26616"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137898" version="1" comment="flash-plugin is earlier than 0:11.2.202.243-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:38087"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94780" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:26712"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94761" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:26712"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94731" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:26712"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94554" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:26712"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94315" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.50.1.11.5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:26712"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94840" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.9-2.3.3.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:26582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94689" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.9-2.3.3.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:26582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94620" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.9-2.3.3.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:26582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94578" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.9-2.3.3.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:26582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94165" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.9-2.3.3.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:26582"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94812" version="1" comment="libproxy-bin is earlier than 0:0.3.0-3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29199"/>
      <state state_ref="oval:org.mitre.oval:ste:26422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94799" version="1" comment="libproxy-python is earlier than 0:0.3.0-3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28747"/>
      <state state_ref="oval:org.mitre.oval:ste:26422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94787" version="1" comment="libproxy-webkit is earlier than 0:0.3.0-3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29108"/>
      <state state_ref="oval:org.mitre.oval:ste:26422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94742" version="1" comment="libproxy-mozjs is earlier than 0:0.3.0-3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28443"/>
      <state state_ref="oval:org.mitre.oval:ste:26422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94708" version="1" comment="libproxy-gnome is earlier than 0:0.3.0-3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29197"/>
      <state state_ref="oval:org.mitre.oval:ste:26422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94584" version="1" comment="libproxy-devel is earlier than 0:0.3.0-3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28270"/>
      <state state_ref="oval:org.mitre.oval:ste:26422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94190" version="1" comment="libproxy-kde is earlier than 0:0.3.0-3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29018"/>
      <state state_ref="oval:org.mitre.oval:ste:26422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94057" version="1" comment="libproxy is earlier than 0:0.3.0-3.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28558"/>
      <state state_ref="oval:org.mitre.oval:ste:26422"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97372" version="1" comment="pango-devel is earlier than 0:1.28.1-3.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15280"/>
      <state state_ref="oval:org.mitre.oval:ste:27101"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97053" version="1" comment="pango is earlier than 0:1.28.1-3.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15101"/>
      <state state_ref="oval:org.mitre.oval:ste:27101"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93971" version="1" comment="openssh-ldap is earlier than 0:5.3p1-81.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29531"/>
      <state state_ref="oval:org.mitre.oval:ste:26504"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93915" version="1" comment="openssh is earlier than 0:5.3p1-81.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14581"/>
      <state state_ref="oval:org.mitre.oval:ste:26504"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93842" version="1" comment="openssh-server is earlier than 0:5.3p1-81.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14544"/>
      <state state_ref="oval:org.mitre.oval:ste:26504"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93815" version="1" comment="openssh-clients is earlier than 0:5.3p1-81.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14409"/>
      <state state_ref="oval:org.mitre.oval:ste:26504"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93589" version="1" comment="pam_ssh_agent_auth is earlier than 0:0.9-81.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29349"/>
      <state state_ref="oval:org.mitre.oval:ste:26592"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93494" version="1" comment="openssh-askpass is earlier than 0:5.3p1-81.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14577"/>
      <state state_ref="oval:org.mitre.oval:ste:26504"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93994" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.5-2.2.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:26162"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93746" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.5-2.2.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:26162"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93700" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.5-2.2.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:26162"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93695" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.5-2.2.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:26162"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93681" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.5-2.2.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:26162"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94685" version="1" comment="libxml2-python is earlier than 0:2.7.6-8.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:26662"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94654" version="1" comment="libxml2-python is earlier than 0:2.6.26-2.1.15.el5_8.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:26515"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94642" version="1" comment="libxml2 is earlier than 0:2.6.26-2.1.15.el5_8.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:26515"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94610" version="1" comment="libxml2-devel is earlier than 0:2.7.6-8.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:26662"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94543" version="1" comment="libxml2 is earlier than 0:2.7.6-8.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:26662"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94291" version="1" comment="libxml2-devel is earlier than 0:2.6.26-2.1.15.el5_8.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:26515"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94284" version="1" comment="libxml2-static is earlier than 0:2.7.6-8.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28876"/>
      <state state_ref="oval:org.mitre.oval:ste:26662"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94652" version="1" comment="kernel-kdump is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94581" version="1" comment="kernel-doc is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94573" version="1" comment="kernel-firmware is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94468" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94437" version="1" comment="kernel is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94317" version="1" comment="python-perf is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94270" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94261" version="1" comment="perf is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94175" version="1" comment="kernel-headers is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94162" version="1" comment="kernel-debug is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94097" version="1" comment="kernel-devel is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94089" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-279.9.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:26530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94505" version="1" comment="qemu-img is earlier than 2:0.12.1.2-2.295.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29180"/>
      <state state_ref="oval:org.mitre.oval:ste:25860"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94436" version="1" comment="qemu-kvm is earlier than 2:0.12.1.2-2.295.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29139"/>
      <state state_ref="oval:org.mitre.oval:ste:25860"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93886" version="1" comment="qemu-kvm-tools is earlier than 2:0.12.1.2-2.295.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28883"/>
      <state state_ref="oval:org.mitre.oval:ste:25860"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93795" version="1" comment="qemu-guest-agent is earlier than 2:0.12.1.2-2.295.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28988"/>
      <state state_ref="oval:org.mitre.oval:ste:25860"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94741" version="1" comment="freeradius-python is earlier than 0:2.1.12-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29886"/>
      <state state_ref="oval:org.mitre.oval:ste:26671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94701" version="1" comment="freeradius-unixODBC is earlier than 0:2.1.12-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13705"/>
      <state state_ref="oval:org.mitre.oval:ste:26671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94683" version="1" comment="freeradius-postgresql is earlier than 0:2.1.12-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14475"/>
      <state state_ref="oval:org.mitre.oval:ste:26671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94668" version="1" comment="freeradius-krb5 is earlier than 0:2.1.12-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29121"/>
      <state state_ref="oval:org.mitre.oval:ste:26671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94622" version="1" comment="freeradius-perl is earlier than 0:2.1.12-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29804"/>
      <state state_ref="oval:org.mitre.oval:ste:26671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94616" version="1" comment="freeradius-mysql is earlier than 0:2.1.12-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14691"/>
      <state state_ref="oval:org.mitre.oval:ste:26671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94566" version="1" comment="freeradius-ldap is earlier than 0:2.1.12-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29871"/>
      <state state_ref="oval:org.mitre.oval:ste:26671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94447" version="1" comment="freeradius is earlier than 0:2.1.12-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14420"/>
      <state state_ref="oval:org.mitre.oval:ste:26671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94426" version="1" comment="freeradius-utils is earlier than 0:2.1.12-4.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29806"/>
      <state state_ref="oval:org.mitre.oval:ste:26671"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94103" version="1" comment="postgresql-devel is earlier than 0:8.4.12-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:26327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94075" version="1" comment="postgresql-docs is earlier than 0:8.4.12-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:26327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94054" version="1" comment="postgresql-pltcl is earlier than 0:8.4.12-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29636"/>
      <state state_ref="oval:org.mitre.oval:ste:26327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94042" version="1" comment="postgresql84-devel is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15349"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94020" version="1" comment="postgresql-server is earlier than 0:8.4.12-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:26327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93970" version="1" comment="postgresql84-tcl is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14440"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93947" version="1" comment="postgresql-contrib is earlier than 0:8.4.12-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:26327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93932" version="1" comment="postgresql84-test is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15176"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93926" version="1" comment="postgresql84-docs is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15371"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93900" version="1" comment="postgresql84-pltcl is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15092"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93881" version="1" comment="postgresql84-server is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15020"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93806" version="1" comment="postgresql-plperl is earlier than 0:8.4.12-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29499"/>
      <state state_ref="oval:org.mitre.oval:ste:26327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93797" version="1" comment="postgresql84-plpython is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15356"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93750" version="1" comment="postgresql-plpython is earlier than 0:8.4.12-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29607"/>
      <state state_ref="oval:org.mitre.oval:ste:26327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93714" version="1" comment="postgresql84-contrib is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15329"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93699" version="1" comment="postgresql84 is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15160"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93632" version="1" comment="postgresql84-python is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15270"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93585" version="1" comment="postgresql-test is earlier than 0:8.4.12-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:26327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93554" version="1" comment="postgresql is earlier than 0:8.4.12-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:26327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93347" version="1" comment="postgresql84-plperl is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14866"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93318" version="1" comment="postgresql-libs is earlier than 0:8.4.12-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:26327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93102" version="1" comment="postgresql84-libs is earlier than 0:8.4.12-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15091"/>
      <state state_ref="oval:org.mitre.oval:ste:26680"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94241" version="1" comment="bind-dyndb-ldap is earlier than 0:1.1.0-0.9.b1.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29468"/>
      <state state_ref="oval:org.mitre.oval:ste:26660"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97531" version="1" comment="mod_dav_svn is earlier than 0:1.6.11-2.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14514"/>
      <state state_ref="oval:org.mitre.oval:ste:27252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97475" version="1" comment="subversion-perl is earlier than 0:1.6.11-2.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14470"/>
      <state state_ref="oval:org.mitre.oval:ste:27252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97422" version="1" comment="subversion-gnome is earlier than 0:1.6.11-2.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29010"/>
      <state state_ref="oval:org.mitre.oval:ste:27252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97296" version="1" comment="subversion-javahl is earlier than 0:1.6.11-2.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15180"/>
      <state state_ref="oval:org.mitre.oval:ste:27252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97140" version="1" comment="subversion-ruby is earlier than 0:1.6.11-2.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15192"/>
      <state state_ref="oval:org.mitre.oval:ste:27252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97080" version="1" comment="subversion-svn2cl is earlier than 0:1.6.11-2.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29417"/>
      <state state_ref="oval:org.mitre.oval:ste:27252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96995" version="1" comment="subversion-devel is earlier than 0:1.6.11-2.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14983"/>
      <state state_ref="oval:org.mitre.oval:ste:27252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96822" version="1" comment="subversion is earlier than 0:1.6.11-2.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15298"/>
      <state state_ref="oval:org.mitre.oval:ste:27252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96604" version="1" comment="subversion-kde is earlier than 0:1.6.11-2.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29565"/>
      <state state_ref="oval:org.mitre.oval:ste:27252"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97585" version="1" comment="kernel-devel is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97584" version="1" comment="kernel-kdump is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97583" version="1" comment="kernel-debug is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97582" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97506" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97403" version="1" comment="kernel-firmware is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97358" version="1" comment="kernel-headers is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97315" version="1" comment="kernel is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97298" version="1" comment="kernel-doc is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97192" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96961" version="1" comment="perf is earlier than 0:2.6.32-71.18.2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27019"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98615" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:27215"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98606" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:27215"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98587" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:27215"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98551" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:27215"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98527" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:27365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98352" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.23.1.9.10.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:27215"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98189" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:27365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98182" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:27365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98164" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:27365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97671" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.40.1.9.10.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:27365"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93885" version="1" comment="sblim-cim-client2-javadoc is earlier than 0:2.1.3-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29529"/>
      <state state_ref="oval:org.mitre.oval:ste:26619"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93741" version="1" comment="sblim-cim-client2-manual is earlier than 0:2.1.3-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29790"/>
      <state state_ref="oval:org.mitre.oval:ste:26619"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93712" version="1" comment="sblim-cim-client2 is earlier than 0:2.1.3-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29642"/>
      <state state_ref="oval:org.mitre.oval:ste:26619"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93899" version="1" comment="rsyslog-gssapi is earlier than 0:5.8.10-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29754"/>
      <state state_ref="oval:org.mitre.oval:ste:26259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93844" version="1" comment="rsyslog-snmp is earlier than 0:5.8.10-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29239"/>
      <state state_ref="oval:org.mitre.oval:ste:26259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93679" version="1" comment="rsyslog-pgsql is earlier than 0:5.8.10-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29801"/>
      <state state_ref="oval:org.mitre.oval:ste:26259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93643" version="1" comment="rsyslog-gnutls is earlier than 0:5.8.10-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29554"/>
      <state state_ref="oval:org.mitre.oval:ste:26259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93518" version="1" comment="rsyslog-mysql is earlier than 0:5.8.10-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28837"/>
      <state state_ref="oval:org.mitre.oval:ste:26259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93427" version="1" comment="rsyslog-relp is earlier than 0:5.8.10-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28815"/>
      <state state_ref="oval:org.mitre.oval:ste:26259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93038" version="1" comment="rsyslog is earlier than 0:5.8.10-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29483"/>
      <state state_ref="oval:org.mitre.oval:ste:26259"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94013" version="1" comment="nss-util is earlier than 0:3.13.3-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29019"/>
      <state state_ref="oval:org.mitre.oval:ste:26618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93861" version="1" comment="nss-tools is earlier than 0:3.13.3-6.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15090"/>
      <state state_ref="oval:org.mitre.oval:ste:26348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93843" version="1" comment="nss-util-devel is earlier than 0:3.13.3-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29207"/>
      <state state_ref="oval:org.mitre.oval:ste:26618"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93729" version="1" comment="nss-pkcs11-devel is earlier than 0:3.13.3-6.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14171"/>
      <state state_ref="oval:org.mitre.oval:ste:26348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93698" version="1" comment="nss-devel is earlier than 0:3.13.3-6.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14656"/>
      <state state_ref="oval:org.mitre.oval:ste:26348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93686" version="1" comment="nss-sysinit is earlier than 0:3.13.3-6.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28504"/>
      <state state_ref="oval:org.mitre.oval:ste:26348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93538" version="1" comment="nss is earlier than 0:3.13.3-6.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14917"/>
      <state state_ref="oval:org.mitre.oval:ste:26348"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93524" version="1" comment="nspr is earlier than 0:4.9-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14745"/>
      <state state_ref="oval:org.mitre.oval:ste:26373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93367" version="1" comment="nspr-devel is earlier than 0:4.9-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15145"/>
      <state state_ref="oval:org.mitre.oval:ste:26373"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94823" version="1" comment="icedtea-web-javadoc is earlier than 0:1.2.2-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29549"/>
      <state state_ref="oval:org.mitre.oval:ste:26270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94673" version="1" comment="icedtea-web is earlier than 0:1.2.2-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29552"/>
      <state state_ref="oval:org.mitre.oval:ste:26270"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:95016" version="1" comment="thunderbird is earlier than 0:10.0.8-2.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26677"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94682" version="1" comment="thunderbird is earlier than 0:10.0.8-2.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26513"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94674" version="1" comment="thunderbird is earlier than 0:10.0.8-2.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:25723"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94643" version="1" comment="thunderbird is earlier than 0:10.0.8-2.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26487"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98724" version="1" comment="openswan-doc is earlier than 0:2.6.32-4.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15278"/>
      <state state_ref="oval:org.mitre.oval:ste:27641"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98644" version="1" comment="openswan is earlier than 0:2.6.21-5.el5_7.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14994"/>
      <state state_ref="oval:org.mitre.oval:ste:27398"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98117" version="1" comment="openswan-doc is earlier than 0:2.6.21-5.el5_7.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15278"/>
      <state state_ref="oval:org.mitre.oval:ste:27398"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98111" version="1" comment="openswan is earlier than 0:2.6.32-4.el6_1.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14994"/>
      <state state_ref="oval:org.mitre.oval:ste:27641"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94146" version="1" comment="kernel-headers is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94141" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94082" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94034" version="1" comment="kernel is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94003" version="1" comment="kernel-doc is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93824" version="1" comment="perf is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93771" version="1" comment="kernel-kdump is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93668" version="1" comment="kernel-devel is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93665" version="1" comment="python-perf is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93630" version="1" comment="kernel-debug is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93202" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93168" version="1" comment="kernel-firmware is earlier than 0:2.6.32-279.1.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:26670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:95071" version="1" comment="firefox is earlier than 0:10.0.8-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26658"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:95006" version="1" comment="firefox is earlier than 0:10.0.8-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26115"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94983" version="1" comment="xulrunner is earlier than 0:10.0.8-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26115"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94736" version="1" comment="firefox is earlier than 0:10.0.8-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26560"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94662" version="1" comment="xulrunner is earlier than 0:10.0.8-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26560"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94541" version="1" comment="firefox is earlier than 0:10.0.8-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26246"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94485" version="1" comment="xulrunner-devel is earlier than 0:10.0.8-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26560"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94408" version="1" comment="xulrunner-devel is earlier than 0:10.0.8-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26246"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94385" version="1" comment="xulrunner-devel is earlier than 0:10.0.8-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26115"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94348" version="1" comment="xulrunner is earlier than 0:10.0.8-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26246"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94035" version="1" comment="cifs-utils is earlier than 0:4.8.1-10.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29603"/>
      <state state_ref="oval:org.mitre.oval:ste:25928"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97348" version="1" comment="php-enchant is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97341" version="1" comment="php-recode is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97337" version="1" comment="php-process is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97320" version="1" comment="php-embedded is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97297" version="1" comment="php-zts is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29304"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97264" version="1" comment="php-pdo is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97251" version="1" comment="php-cli is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97244" version="1" comment="php-imap is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97222" version="1" comment="php-xml is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97186" version="1" comment="php-mysql is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97173" version="1" comment="php-intl is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97160" version="1" comment="php-devel is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97139" version="1" comment="php-pspell is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97136" version="1" comment="php-bcmath is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97116" version="1" comment="php-odbc is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97069" version="1" comment="php-pgsql is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97022" version="1" comment="php-xmlrpc is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97011" version="1" comment="php-ldap is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96975" version="1" comment="php-soap is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96935" version="1" comment="php-mbstring is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96866" version="1" comment="php-common is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96842" version="1" comment="php is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96765" version="1" comment="php-tidy is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28881"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96729" version="1" comment="php-snmp is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96385" version="1" comment="php-gd is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96379" version="1" comment="php-dba is earlier than 0:5.3.2-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:27034"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93976" version="1" comment="sos is earlier than 0:2.2-29.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29415"/>
      <state state_ref="oval:org.mitre.oval:ste:26568"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94874" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94842" version="1" comment="kernel-firmware is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94837" version="1" comment="python-perf is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94818" version="1" comment="kernel-kdump is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94807" version="1" comment="perf is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94783" version="1" comment="kernel-doc is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94779" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94661" version="1" comment="kernel-debug is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94653" version="1" comment="kernel is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94583" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94431" version="1" comment="kernel-devel is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94260" version="1" comment="kernel-headers is earlier than 0:2.6.32-279.14.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:26571"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94603" version="1" comment="libxslt-python is earlier than 0:1.1.26-2.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14955"/>
      <state state_ref="oval:org.mitre.oval:ste:26359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94580" version="1" comment="libxslt-python is earlier than 0:1.1.17-4.el5_8.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14955"/>
      <state state_ref="oval:org.mitre.oval:ste:26665"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94515" version="1" comment="libxslt is earlier than 0:1.1.17-4.el5_8.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15147"/>
      <state state_ref="oval:org.mitre.oval:ste:26665"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94414" version="1" comment="libxslt-devel is earlier than 0:1.1.26-2.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15150"/>
      <state state_ref="oval:org.mitre.oval:ste:26359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94308" version="1" comment="libxslt is earlier than 0:1.1.26-2.el6_3.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15147"/>
      <state state_ref="oval:org.mitre.oval:ste:26359"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94297" version="1" comment="libxslt-devel is earlier than 0:1.1.17-4.el5_8.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15150"/>
      <state state_ref="oval:org.mitre.oval:ste:26665"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94856" version="1" comment="mysql-embedded-devel is earlier than 0:5.1.66-2.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28807"/>
      <state state_ref="oval:org.mitre.oval:ste:26679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94815" version="1" comment="mysql is earlier than 0:5.1.66-2.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14355"/>
      <state state_ref="oval:org.mitre.oval:ste:26679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94801" version="1" comment="mysql-bench is earlier than 0:5.1.66-2.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14400"/>
      <state state_ref="oval:org.mitre.oval:ste:26679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94759" version="1" comment="mysql-server is earlier than 0:5.1.66-2.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14342"/>
      <state state_ref="oval:org.mitre.oval:ste:26679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94744" version="1" comment="mysql-devel is earlier than 0:5.1.66-2.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14481"/>
      <state state_ref="oval:org.mitre.oval:ste:26679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94660" version="1" comment="mysql-embedded is earlier than 0:5.1.66-2.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28870"/>
      <state state_ref="oval:org.mitre.oval:ste:26679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94557" version="1" comment="mysql-libs is earlier than 0:5.1.66-2.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28723"/>
      <state state_ref="oval:org.mitre.oval:ste:26679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94302" version="1" comment="mysql-test is earlier than 0:5.1.66-2.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14941"/>
      <state state_ref="oval:org.mitre.oval:ste:26679"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94129" version="1" comment="libtiff-static is earlier than 0:3.9.4-6.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29708"/>
      <state state_ref="oval:org.mitre.oval:ste:26510"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94058" version="1" comment="libtiff is earlier than 0:3.9.4-6.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:26510"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94023" version="1" comment="libtiff-devel is earlier than 0:3.9.4-6.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:26510"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93837" version="1" comment="libtiff-devel is earlier than 0:3.8.2-15.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:26272"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93166" version="1" comment="libtiff is earlier than 0:3.8.2-15.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:26272"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97724" version="1" comment="spice-xpi is earlier than 0:2.4-1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30089"/>
      <state state_ref="oval:org.mitre.oval:ste:27172"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97564" version="1" comment="libcgroup is earlier than 0:0.36.1-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30141"/>
      <state state_ref="oval:org.mitre.oval:ste:26900"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97510" version="1" comment="libcgroup-devel is earlier than 0:0.36.1-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29571"/>
      <state state_ref="oval:org.mitre.oval:ste:26900"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97303" version="1" comment="libcgroup-pam is earlier than 0:0.36.1-6.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30084"/>
      <state state_ref="oval:org.mitre.oval:ste:26900"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97406" version="1" comment="thunderbird is earlier than 0:3.1.8-4.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:27099"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94961" version="1" comment="firefox is earlier than 0:10.0.6-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26417"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94776" version="1" comment="firefox is earlier than 0:10.0.6-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26719"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94749" version="1" comment="xulrunner-devel is earlier than 0:10.0.6-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26719"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94352" version="1" comment="xulrunner is earlier than 0:10.0.6-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26719"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94164" version="1" comment="xulrunner is earlier than 0:10.0.6-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26517"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94072" version="1" comment="firefox is earlier than 0:10.0.6-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26517"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94048" version="1" comment="xulrunner-devel is earlier than 0:10.0.6-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26517"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93936" version="1" comment="xulrunner-devel is earlier than 0:10.0.6-2.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26401"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93905" version="1" comment="firefox is earlier than 0:10.0.6-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26643"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93581" version="1" comment="xulrunner is earlier than 0:10.0.6-2.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26401"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94498" version="1" comment="java-1.7.0-oracle-plugin is earlier than 1:1.7.0.7-1jpp.5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29211"/>
      <state state_ref="oval:org.mitre.oval:ste:26630"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94443" version="1" comment="java-1.7.0-oracle-devel is earlier than 1:1.7.0.7-1jpp.5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28861"/>
      <state state_ref="oval:org.mitre.oval:ste:26630"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94239" version="1" comment="java-1.7.0-oracle is earlier than 1:1.7.0.7-1jpp.5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28501"/>
      <state state_ref="oval:org.mitre.oval:ste:26630"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94180" version="1" comment="java-1.7.0-oracle-src is earlier than 1:1.7.0.7-1jpp.5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28836"/>
      <state state_ref="oval:org.mitre.oval:ste:26630"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94176" version="1" comment="java-1.7.0-oracle-jdbc is earlier than 1:1.7.0.7-1jpp.5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28813"/>
      <state state_ref="oval:org.mitre.oval:ste:26630"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94381" version="1" comment="libreoffice-langpack-de is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29128"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94313" version="1" comment="libreoffice-base is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29800"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94312" version="1" comment="autocorr-sr is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29788"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94299" version="1" comment="libreoffice-langpack-bn is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29889"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94295" version="1" comment="autocorr-fi is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29277"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94292" version="1" comment="autocorr-sv is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29661"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94289" version="1" comment="libreoffice-langpack-ur is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29726"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94286" version="1" comment="libreoffice-graphicfilter is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29203"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94280" version="1" comment="libreoffice-langpack-eu is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29781"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94279" version="1" comment="libreoffice-langpack-ta is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29684"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94276" version="1" comment="libreoffice-langpack-lt is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29232"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94275" version="1" comment="libreoffice-langpack-el is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29813"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94273" version="1" comment="autocorr-vi is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29669"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94272" version="1" comment="autocorr-pl is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29526"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94271" version="1" comment="libreoffice-langpack-et is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29859"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94257" version="1" comment="autocorr-eu is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29083"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94250" version="1" comment="libreoffice-langpack-th is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29002"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94248" version="1" comment="autocorr-pt is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29205"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94245" version="1" comment="libreoffice-langpack-ve is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29817"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94243" version="1" comment="libreoffice-core is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29705"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94238" version="1" comment="autocorr-fr is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29693"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94237" version="1" comment="libreoffice-langpack-nn is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29827"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94236" version="1" comment="libreoffice-langpack-pa is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29532"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94235" version="1" comment="libreoffice-langpack-ar is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29588"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94234" version="1" comment="libreoffice-langpack-zu is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29896"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94233" version="1" comment="autocorr-en is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29663"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94232" version="1" comment="libreoffice-langpack-xh is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29650"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94227" version="1" comment="libreoffice-langpack-sv is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29822"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94223" version="1" comment="libreoffice-langpack-nb is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29838"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94220" version="1" comment="libreoffice-sdk-doc is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29510"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94214" version="1" comment="autocorr-ko is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29385"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94211" version="1" comment="libreoffice-langpack-ca is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29836"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94210" version="1" comment="libreoffice-rhino is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29794"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94203" version="1" comment="libreoffice-writer is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29810"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94201" version="1" comment="autocorr-lt is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29480"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94195" version="1" comment="libreoffice-langpack-sr is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29538"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94191" version="1" comment="libreoffice-langpack-af is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29778"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94189" version="1" comment="libreoffice-langpack-mai is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29785"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94174" version="1" comment="libreoffice-presenter-screen is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29259"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94167" version="1" comment="libreoffice-langpack-cy is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29793"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94159" version="1" comment="libreoffice-math is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29589"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94156" version="1" comment="autocorr-hr is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29759"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94152" version="1" comment="autocorr-cs is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29706"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94148" version="1" comment="libreoffice-report-builder is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29689"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94144" version="1" comment="libreoffice-langpack-hi is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29470"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94140" version="1" comment="libreoffice-langpack-es is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29598"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94137" version="1" comment="autocorr-ru is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29309"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94135" version="1" comment="libreoffice-langpack-ko is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29818"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94126" version="1" comment="libreoffice-langpack-nr is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29721"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94124" version="1" comment="libreoffice-langpack-cs is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29405"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94121" version="1" comment="libreoffice-testtools is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29765"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94120" version="1" comment="autocorr-lb is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29334"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94118" version="1" comment="libreoffice-langpack-sk is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29774"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94117" version="1" comment="libreoffice-langpack-ml is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29820"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94115" version="1" comment="libreoffice-headless is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29274"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94114" version="1" comment="libreoffice-calc is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29290"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94108" version="1" comment="libreoffice-langpack-ro is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29544"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94086" version="1" comment="libreoffice-langpack-dz is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29576"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94083" version="1" comment="libreoffice-langpack-ts is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29789"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94069" version="1" comment="libreoffice-langpack-pl is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29828"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94066" version="1" comment="autocorr-zh is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29217"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94061" version="1" comment="autocorr-mn is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29704"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94045" version="1" comment="libreoffice-langpack-pt-PT is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29878"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94028" version="1" comment="libreoffice-langpack-tn is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28879"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94027" version="1" comment="libreoffice-langpack-or is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29840"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94022" version="1" comment="autocorr-ga is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29261"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94019" version="1" comment="libreoffice-langpack-te is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29824"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94012" version="1" comment="autocorr-fa is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29686"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94010" version="1" comment="libreoffice-langpack-mr is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29853"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94008" version="1" comment="libreoffice-opensymbol-fonts is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29649"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94007" version="1" comment="libreoffice-langpack-hu is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29688"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93998" version="1" comment="libreoffice-langpack-as is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29452"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93993" version="1" comment="libreoffice-langpack-hr is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29753"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93977" version="1" comment="libreoffice-langpack-ru is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29844"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93975" version="1" comment="autocorr-tr is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29654"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93974" version="1" comment="libreoffice-ogltrans is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29657"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93961" version="1" comment="libreoffice-langpack-fr is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29852"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93951" version="1" comment="libreoffice-langpack-zh-Hant is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29829"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93934" version="1" comment="libreoffice-draw is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29875"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93917" version="1" comment="autocorr-sk is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29594"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93916" version="1" comment="autocorr-es is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29422"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93908" version="1" comment="libreoffice-impress is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29733"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93898" version="1" comment="autocorr-bg is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29697"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93884" version="1" comment="libreoffice-langpack-ga is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29365"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93875" version="1" comment="libreoffice-langpack-en is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29328"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93857" version="1" comment="libreoffice-langpack-gu is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28871"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93839" version="1" comment="libreoffice-langpack-nso is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28920"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93835" version="1" comment="libreoffice-langpack-st is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29634"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93830" version="1" comment="autocorr-nl is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29457"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93829" version="1" comment="libreoffice-langpack-uk is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29660"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93825" version="1" comment="libreoffice-langpack-pt-BR is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29737"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93820" version="1" comment="autocorr-da is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28721"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93809" version="1" comment="libreoffice-langpack-nl is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29542"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93802" version="1" comment="autocorr-hu is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29036"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93790" version="1" comment="libreoffice-langpack-zh-Hans is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28894"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93775" version="1" comment="libreoffice-langpack-ms is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29833"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93752" version="1" comment="libreoffice-langpack-he is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29712"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93732" version="1" comment="libreoffice-emailmerge is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29775"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93716" version="1" comment="libreoffice-bsh is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29323"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93701" version="1" comment="autocorr-it is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29418"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93672" version="1" comment="libreoffice-wiki-publisher is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28904"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93666" version="1" comment="libreoffice-langpack-ja is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29396"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93664" version="1" comment="autocorr-sl is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29593"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93633" version="1" comment="autocorr-ja is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29443"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93597" version="1" comment="libreoffice-langpack-da is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29910"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93583" version="1" comment="libreoffice-langpack-ss is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29864"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93530" version="1" comment="libreoffice-langpack-sl is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29507"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93496" version="1" comment="libreoffice-langpack-it is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29762"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93491" version="1" comment="libreoffice is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29803"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93461" version="1" comment="libreoffice-presentation-minimizer is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29854"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93445" version="1" comment="libreoffice-ure is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29555"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93411" version="1" comment="libreoffice-langpack-fi is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29311"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93382" version="1" comment="autocorr-de is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29184"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93362" version="1" comment="libreoffice-gdb-debug-support is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29596"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93354" version="1" comment="libreoffice-langpack-gl is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29718"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93334" version="1" comment="libreoffice-xsltfilter is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29901"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93319" version="1" comment="libreoffice-langpack-bg is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29918"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93308" version="1" comment="libreoffice-javafilter is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29845"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93303" version="1" comment="libreoffice-pdfimport is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29692"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93299" version="1" comment="libreoffice-pyuno is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29757"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93292" version="1" comment="libreoffice-langpack-tr is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29196"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93258" version="1" comment="libreoffice-langpack-kn is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29702"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93245" version="1" comment="libreoffice-sdk is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28877"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93215" version="1" comment="autocorr-af is earlier than 1:3.4.5.2-16.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28756"/>
      <state state_ref="oval:org.mitre.oval:ste:26541"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94700" version="1" comment="qpid-cpp-server-store is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29579"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94667" version="1" comment="ruby-qpid-qmf is earlier than 0:0.14-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29694"/>
      <state state_ref="oval:org.mitre.oval:ste:25698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94659" version="1" comment="qpid-cpp-server-xml is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29605"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94648" version="1" comment="rh-qpid-cpp-tests is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29772"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94637" version="1" comment="qpid-cpp-server-ssl is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29767"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94629" version="1" comment="qpid-cpp-client-ssl is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29764"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94594" version="1" comment="qpid-cpp-client-rdma is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29263"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94507" version="1" comment="qpid-cpp is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29648"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94473" version="1" comment="python-qpid is earlier than 0:0.14-11.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29842"/>
      <state state_ref="oval:org.mitre.oval:ste:26173"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94452" version="1" comment="qpid-cpp-client-devel is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29768"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94430" version="1" comment="qpid-cpp-client is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29856"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94345" version="1" comment="python-qpid-qmf is earlier than 0:0.14-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29676"/>
      <state state_ref="oval:org.mitre.oval:ste:25698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94331" version="1" comment="qpid-cpp-server-devel is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29581"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94329" version="1" comment="qpid-cpp-server is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29711"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94259" version="1" comment="qpid-qmf-devel is earlier than 0:0.14-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29306"/>
      <state state_ref="oval:org.mitre.oval:ste:25698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94249" version="1" comment="qpid-cpp-server-rdma is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29643"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94198" version="1" comment="qpid-qmf is earlier than 0:0.14-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29390"/>
      <state state_ref="oval:org.mitre.oval:ste:25698"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94157" version="1" comment="qpid-cpp-server-cluster is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29617"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93959" version="1" comment="qpid-tools is earlier than 0:0.14-6.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29303"/>
      <state state_ref="oval:org.mitre.oval:ste:26608"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93742" version="1" comment="qpid-cpp-client-devel-docs is earlier than 0:0.14-22.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29680"/>
      <state state_ref="oval:org.mitre.oval:ste:26682"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94147" version="1" comment="openjpeg-libs is earlier than 0:1.3-8.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29623"/>
      <state state_ref="oval:org.mitre.oval:ste:26434"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93953" version="1" comment="openjpeg is earlier than 0:1.3-8.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29353"/>
      <state state_ref="oval:org.mitre.oval:ste:26434"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93249" version="1" comment="openjpeg-devel is earlier than 0:1.3-8.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29260"/>
      <state state_ref="oval:org.mitre.oval:ste:26434"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93950" version="1" comment="openldap is earlier than 0:2.4.23-26.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14650"/>
      <state state_ref="oval:org.mitre.oval:ste:26290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93945" version="1" comment="openldap-devel is earlier than 0:2.4.23-26.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14680"/>
      <state state_ref="oval:org.mitre.oval:ste:26290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93811" version="1" comment="openldap-clients is earlier than 0:2.4.23-26.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13745"/>
      <state state_ref="oval:org.mitre.oval:ste:26290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93615" version="1" comment="openldap-servers-sql is earlier than 0:2.4.23-26.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14387"/>
      <state state_ref="oval:org.mitre.oval:ste:26290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93046" version="1" comment="openldap-servers is earlier than 0:2.4.23-26.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14676"/>
      <state state_ref="oval:org.mitre.oval:ste:26290"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97489" version="1" comment="dhcp-devel is earlier than 12:4.1.1-12.P1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3630"/>
      <state state_ref="oval:org.mitre.oval:ste:26932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97276" version="1" comment="dhclient is earlier than 12:4.1.1-12.P1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15218"/>
      <state state_ref="oval:org.mitre.oval:ste:26932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96539" version="1" comment="dhcp is earlier than 12:4.1.1-12.P1.el6_0.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3459"/>
      <state state_ref="oval:org.mitre.oval:ste:26932"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94561" version="1" comment="flash-plugin is earlier than 0:11.2.202.258-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:26758"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137796" version="1" comment="flash-plugin is earlier than 0:11.2.202.258-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:37963"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97862" version="1" comment="apr-devel is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15174"/>
      <state state_ref="oval:org.mitre.oval:ste:26796"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97743" version="1" comment="apr-devel is earlier than 0:1.2.7-11.el5_6.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15174"/>
      <state state_ref="oval:org.mitre.oval:ste:26788"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97624" version="1" comment="apr is earlier than 0:1.2.7-11.el5_6.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15116"/>
      <state state_ref="oval:org.mitre.oval:ste:26788"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97591" version="1" comment="apr is earlier than 0:1.3.9-3.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15116"/>
      <state state_ref="oval:org.mitre.oval:ste:26796"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97588" version="1" comment="apr-docs is earlier than 0:1.2.7-11.el5_6.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15034"/>
      <state state_ref="oval:org.mitre.oval:ste:26788"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94104" version="1" comment="php-process is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94064" version="1" comment="php-zts is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29304"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94063" version="1" comment="php-enchant is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94060" version="1" comment="php-recode is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93988" version="1" comment="php-bcmath is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93924" version="1" comment="php-mysql is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93923" version="1" comment="php-snmp is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93912" version="1" comment="php-imap is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93903" version="1" comment="php-odbc is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93897" version="1" comment="php-soap is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93896" version="1" comment="php-embedded is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93878" version="1" comment="php-xml is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93876" version="1" comment="php is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93833" version="1" comment="php-pdo is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93832" version="1" comment="php-cli is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93810" version="1" comment="php-intl is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93724" version="1" comment="php-mbstring is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93678" version="1" comment="php-pspell is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93671" version="1" comment="php-pgsql is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93656" version="1" comment="php-common is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93536" version="1" comment="php-tidy is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28881"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93431" version="1" comment="php-devel is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93250" version="1" comment="php-xmlrpc is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93136" version="1" comment="php-dba is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93121" version="1" comment="php-gd is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93118" version="1" comment="php-ldap is earlier than 0:5.3.3-14.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:26441"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98085" version="1" comment="flash-plugin is earlier than 0:10.3.181.22-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:26808"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97939" version="1" comment="flash-plugin is earlier than 0:10.3.181.22-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:26840"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94208" version="1" comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:26531"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94192" version="1" comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:26531"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94170" version="1" comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:26531"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94163" version="1" comment="bind-libs is earlier than 30:9.3.6-20.P1.el5_8.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:26577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94122" version="1" comment="bind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:26577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94099" version="1" comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:26531"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94087" version="1" comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:26531"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94081" version="1" comment="bind-sdb is earlier than 30:9.3.6-20.P1.el5_8.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:26577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94079" version="1" comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:26531"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94049" version="1" comment="bind-utils is earlier than 30:9.3.6-20.P1.el5_8.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:26577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93963" version="1" comment="caching-nameserver is earlier than 30:9.3.6-20.P1.el5_8.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14701"/>
      <state state_ref="oval:org.mitre.oval:ste:26577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93721" version="1" comment="bind is earlier than 30:9.3.6-20.P1.el5_8.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:26577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93566" version="1" comment="bind-chroot is earlier than 30:9.3.6-20.P1.el5_8.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:26577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93247" version="1" comment="bind-libbind-devel is earlier than 30:9.3.6-20.P1.el5_8.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14729"/>
      <state state_ref="oval:org.mitre.oval:ste:26577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93150" version="1" comment="busybox-petitboot is earlier than 1:1.15.1-15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29516"/>
      <state state_ref="oval:org.mitre.oval:ste:26539"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92987" version="1" comment="busybox is earlier than 1:1.15.1-15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14087"/>
      <state state_ref="oval:org.mitre.oval:ste:26539"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97928" version="1" comment="dovecot-pgsql is earlier than 1:2.0.9-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30241"/>
      <state state_ref="oval:org.mitre.oval:ste:26722"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97891" version="1" comment="dovecot-pigeonhole is earlier than 1:2.0.9-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30040"/>
      <state state_ref="oval:org.mitre.oval:ste:26722"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97571" version="1" comment="dovecot-devel is earlier than 1:2.0.9-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4212"/>
      <state state_ref="oval:org.mitre.oval:ste:26722"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97459" version="1" comment="dovecot-mysql is earlier than 1:2.0.9-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29698"/>
      <state state_ref="oval:org.mitre.oval:ste:26722"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97340" version="1" comment="dovecot is earlier than 1:2.0.9-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:3572"/>
      <state state_ref="oval:org.mitre.oval:ste:26722"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93937" version="1" comment="mysql-bench is earlier than 0:5.1.61-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14400"/>
      <state state_ref="oval:org.mitre.oval:ste:26209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93663" version="1" comment="mysql-server is earlier than 0:5.1.61-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14342"/>
      <state state_ref="oval:org.mitre.oval:ste:26209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93624" version="1" comment="mysql is earlier than 0:5.1.61-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14355"/>
      <state state_ref="oval:org.mitre.oval:ste:26209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93608" version="1" comment="mysql-embedded-devel is earlier than 0:5.1.61-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28807"/>
      <state state_ref="oval:org.mitre.oval:ste:26209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93579" version="1" comment="mysql-libs is earlier than 0:5.1.61-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28723"/>
      <state state_ref="oval:org.mitre.oval:ste:26209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93505" version="1" comment="mysql-embedded is earlier than 0:5.1.61-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28870"/>
      <state state_ref="oval:org.mitre.oval:ste:26209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93398" version="1" comment="mysql-test is earlier than 0:5.1.61-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14941"/>
      <state state_ref="oval:org.mitre.oval:ste:26209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93275" version="1" comment="mysql-devel is earlier than 0:5.1.61-4.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14481"/>
      <state state_ref="oval:org.mitre.oval:ste:26209"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98078" version="1" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14925"/>
      <state state_ref="oval:org.mitre.oval:ste:27354"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98051" version="1" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15114"/>
      <state state_ref="oval:org.mitre.oval:ste:27354"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98022" version="1" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14531"/>
      <state state_ref="oval:org.mitre.oval:ste:27354"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97976" version="1" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14889"/>
      <state state_ref="oval:org.mitre.oval:ste:27354"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97919" version="1" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.39.1.9.8.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15274"/>
      <state state_ref="oval:org.mitre.oval:ste:27354"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94471" version="1" comment="glibc-static is earlier than 0:2.12-1.80.el6_3.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29528"/>
      <state state_ref="oval:org.mitre.oval:ste:26192"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94367" version="1" comment="glibc-utils is earlier than 0:2.12-1.80.el6_3.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:26192"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94347" version="1" comment="glibc-common is earlier than 0:2.12-1.80.el6_3.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:26192"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94274" version="1" comment="glibc is earlier than 0:2.12-1.80.el6_3.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:26192"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94209" version="1" comment="nscd is earlier than 0:2.12-1.80.el6_3.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:26192"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93965" version="1" comment="glibc-headers is earlier than 0:2.12-1.80.el6_3.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:26192"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93938" version="1" comment="glibc-devel is earlier than 0:2.12-1.80.el6_3.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:26192"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94265" version="1" comment="openjpeg-libs is earlier than 0:1.3-9.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29623"/>
      <state state_ref="oval:org.mitre.oval:ste:26322"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94244" version="1" comment="openjpeg-devel is earlier than 0:1.3-9.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29260"/>
      <state state_ref="oval:org.mitre.oval:ste:26322"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94005" version="1" comment="openjpeg is earlier than 0:1.3-9.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29353"/>
      <state state_ref="oval:org.mitre.oval:ste:26322"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97231" version="1" comment="pango is earlier than 0:1.28.1-3.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15101"/>
      <state state_ref="oval:org.mitre.oval:ste:27116"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97059" version="1" comment="pango-devel is earlier than 0:1.28.1-3.el6_0.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15280"/>
      <state state_ref="oval:org.mitre.oval:ste:27116"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137822" version="1" comment="pango is earlier than 0:1.14.9-8.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15101"/>
      <state state_ref="oval:org.mitre.oval:ste:38197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137760" version="1" comment="pango-debuginfo is earlier than 0:1.28.1-3.el6_0.3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43161"/>
      <state state_ref="oval:org.mitre.oval:ste:37811"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137637" version="1" comment="pango-devel is earlier than 0:1.14.9-8.el5_6.2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15280"/>
      <state state_ref="oval:org.mitre.oval:ste:38197"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94707" version="1" comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:26437"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94697" version="1" comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:26437"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94630" version="1" comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:26437"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94463" version="1" comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:26437"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94441" version="1" comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:26437"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94324" version="1" comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:26437"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94041" version="1" comment="389-ds-base is earlier than 0:1.2.10.2-18.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28953"/>
      <state state_ref="oval:org.mitre.oval:ste:26601"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93480" version="1" comment="389-ds-base-libs is earlier than 0:1.2.10.2-18.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28949"/>
      <state state_ref="oval:org.mitre.oval:ste:26601"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93224" version="1" comment="389-ds-base-devel is earlier than 0:1.2.10.2-18.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29162"/>
      <state state_ref="oval:org.mitre.oval:ste:26601"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93847" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93785" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93709" version="1" comment="kernel-debug is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93651" version="1" comment="kernel-devel is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93645" version="1" comment="kernel is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93623" version="1" comment="kernel-firmware is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93514" version="1" comment="kernel-kdump is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93499" version="1" comment="python-perf is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93487" version="1" comment="perf is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93437" version="1" comment="kernel-doc is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93379" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92933" version="1" comment="kernel-headers is earlier than 0:2.6.32-220.23.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:26338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93350" version="1" comment="freetype-devel is earlier than 0:2.2.1-31.el5_8.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:25869"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93348" version="1" comment="freetype is earlier than 0:2.3.11-6.el6_2.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:26139"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93242" version="1" comment="freetype-demos is earlier than 0:2.3.11-6.el6_2.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:26139"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93238" version="1" comment="freetype-devel is earlier than 0:2.3.11-6.el6_2.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14561"/>
      <state state_ref="oval:org.mitre.oval:ste:26139"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93043" version="1" comment="freetype is earlier than 0:2.2.1-31.el5_8.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14103"/>
      <state state_ref="oval:org.mitre.oval:ste:25869"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92695" version="1" comment="freetype-demos is earlier than 0:2.2.1-31.el5_8.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14713"/>
      <state state_ref="oval:org.mitre.oval:ste:25869"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93071" version="1" comment="glibc is earlier than 0:2.12-1.47.el6_2.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14142"/>
      <state state_ref="oval:org.mitre.oval:ste:26227"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93051" version="1" comment="glibc-static is earlier than 0:2.12-1.47.el6_2.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29528"/>
      <state state_ref="oval:org.mitre.oval:ste:26227"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93013" version="1" comment="glibc-utils is earlier than 0:2.12-1.47.el6_2.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14059"/>
      <state state_ref="oval:org.mitre.oval:ste:26227"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92846" version="1" comment="glibc-common is earlier than 0:2.12-1.47.el6_2.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14374"/>
      <state state_ref="oval:org.mitre.oval:ste:26227"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92834" version="1" comment="glibc-devel is earlier than 0:2.12-1.47.el6_2.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14346"/>
      <state state_ref="oval:org.mitre.oval:ste:26227"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92701" version="1" comment="glibc-headers is earlier than 0:2.12-1.47.el6_2.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13936"/>
      <state state_ref="oval:org.mitre.oval:ste:26227"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92200" version="1" comment="nscd is earlier than 0:2.12-1.47.el6_2.9" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14360"/>
      <state state_ref="oval:org.mitre.oval:ste:26227"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97050" version="1" comment="evince-libs is earlier than 0:2.28.2-14.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29995"/>
      <state state_ref="oval:org.mitre.oval:ste:26994"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97020" version="1" comment="evince is earlier than 0:2.28.2-14.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:4303"/>
      <state state_ref="oval:org.mitre.oval:ste:26994"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96824" version="1" comment="evince-devel is earlier than 0:2.28.2-14.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29881"/>
      <state state_ref="oval:org.mitre.oval:ste:26994"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96245" version="1" comment="evince-dvi is earlier than 0:2.28.2-14.el6_0.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29832"/>
      <state state_ref="oval:org.mitre.oval:ste:26994"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94025" version="1" comment="kernel-doc is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94006" version="1" comment="kernel-debug is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93942" version="1" comment="kernel-headers is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93920" version="1" comment="python-perf is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93892" version="1" comment="kernel is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93822" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93751" version="1" comment="kernel-kdump is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93728" version="1" comment="kernel-firmware is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93650" version="1" comment="perf is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93644" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93525" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93063" version="1" comment="kernel-devel is earlier than 0:2.6.32-279.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:26424"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98638" version="1" comment="mod_ssl is earlier than 0:2.2.15-9.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14422"/>
      <state state_ref="oval:org.mitre.oval:ste:27248"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98619" version="1" comment="httpd-tools is earlier than 0:2.2.15-9.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29273"/>
      <state state_ref="oval:org.mitre.oval:ste:27248"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98546" version="1" comment="httpd-manual is earlier than 0:2.2.15-9.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14457"/>
      <state state_ref="oval:org.mitre.oval:ste:27248"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98542" version="1" comment="httpd is earlier than 0:2.2.15-9.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14173"/>
      <state state_ref="oval:org.mitre.oval:ste:27248"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98515" version="1" comment="httpd-devel is earlier than 0:2.2.15-9.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14256"/>
      <state state_ref="oval:org.mitre.oval:ste:27248"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93381" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93364" version="1" comment="kernel-firmware is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93356" version="1" comment="python-perf is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93235" version="1" comment="perf is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93175" version="1" comment="kernel-debug is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93160" version="1" comment="kernel-headers is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93123" version="1" comment="kernel is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92954" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92912" version="1" comment="kernel-kdump is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92760" version="1" comment="kernel-doc is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92715" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92566" version="1" comment="kernel-devel is earlier than 0:2.6.32-220.13.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:26305"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94517" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:26193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94510" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:26193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94371" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:26193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94187" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:26193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94179" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:26193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94059" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:26193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93561" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.11.0-1jpp.1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:26193"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137919" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:38031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137905" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:38031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137867" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:38031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137790" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:38031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137773" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:38031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137674" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:38031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137558" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:38031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137154" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.11.0-1jpp.1.el5_8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:38031"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93986" version="1" comment="net-snmp-libs is earlier than 1:5.5-41.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14316"/>
      <state state_ref="oval:org.mitre.oval:ste:26652"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93891" version="1" comment="net-snmp-python is earlier than 1:5.5-41.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29748"/>
      <state state_ref="oval:org.mitre.oval:ste:26652"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93778" version="1" comment="net-snmp-perl is earlier than 1:5.5-41.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14516"/>
      <state state_ref="oval:org.mitre.oval:ste:26652"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93743" version="1" comment="net-snmp is earlier than 1:5.5-41.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14390"/>
      <state state_ref="oval:org.mitre.oval:ste:26652"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93573" version="1" comment="net-snmp-devel is earlier than 1:5.5-41.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14339"/>
      <state state_ref="oval:org.mitre.oval:ste:26652"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93451" version="1" comment="net-snmp-utils is earlier than 1:5.5-41.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14287"/>
      <state state_ref="oval:org.mitre.oval:ste:26652"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94472" version="1" comment="python-paste-script is earlier than 0:1.7.3-5.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29766"/>
      <state state_ref="oval:org.mitre.oval:ste:26222"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98007" version="1" comment="kernel is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97849" version="1" comment="kernel-doc is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97838" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97797" version="1" comment="kernel-debug is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97796" version="1" comment="kernel-headers is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97685" version="1" comment="perf is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97587" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97497" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97451" version="1" comment="kernel-kdump is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97253" version="1" comment="kernel-devel is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97104" version="1" comment="kernel-firmware is earlier than 0:2.6.32-131.2.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:27336"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98234" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.18-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27447"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98209" version="1" comment="xulrunner is earlier than 0:1.9.2.18-2.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27447"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98128" version="1" comment="firefox is earlier than 0:3.6.18-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:27376"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137886" version="1" comment="firefox is earlier than 0:3.6.18-1.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:37272"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137844" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.18-2.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:38237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137812" version="1" comment="xulrunner-debuginfo is earlier than 0:1.9.2.18-2.el6_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43432"/>
      <state state_ref="oval:org.mitre.oval:ste:38187"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137646" version="1" comment="firefox-debuginfo is earlier than 0:3.6.18-1.el6_1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43227"/>
      <state state_ref="oval:org.mitre.oval:ste:38269"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137643" version="1" comment="firefox is earlier than 0:3.6.18-1.el5.centos" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:38170"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137543" version="1" comment="xulrunner is earlier than 0:1.9.2.18-2.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:38237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94933" version="1" comment="xulrunner is earlier than 0:10.0.7-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94875" version="1" comment="xulrunner-devel is earlier than 0:10.0.7-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94509" version="1" comment="firefox is earlier than 0:10.0.7-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26610"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94474" version="1" comment="firefox is earlier than 0:10.0.7-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94434" version="1" comment="xulrunner-devel is earlier than 0:10.0.7-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94361" version="1" comment="firefox is earlier than 0:10.0.7-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26431"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94337" version="1" comment="xulrunner is earlier than 0:10.0.7-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26472"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94093" version="1" comment="xulrunner-devel is earlier than 0:10.0.7-2.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26146"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93780" version="1" comment="xulrunner is earlier than 0:10.0.7-2.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26146"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93506" version="1" comment="firefox is earlier than 0:10.0.7-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26414"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97240" version="1" comment="webkitgtk-doc is earlier than 0:1.2.6-2.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30175"/>
      <state state_ref="oval:org.mitre.oval:ste:27025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96964" version="1" comment="webkitgtk is earlier than 0:1.2.6-2.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30031"/>
      <state state_ref="oval:org.mitre.oval:ste:27025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96535" version="1" comment="webkitgtk-devel is earlier than 0:1.2.6-2.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30050"/>
      <state state_ref="oval:org.mitre.oval:ste:27025"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93869" version="1" comment="php-pecl-apc-devel is earlier than 0:3.1.9-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29735"/>
      <state state_ref="oval:org.mitre.oval:ste:26482"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93634" version="1" comment="php-pecl-apc is earlier than 0:3.1.9-2.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29671"/>
      <state state_ref="oval:org.mitre.oval:ste:26482"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94967" version="1" comment="xulrunner is earlier than 0:10.0.5-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26678"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94740" version="1" comment="xulrunner-devel is earlier than 0:10.0.5-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26678"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94639" version="1" comment="firefox is earlier than 0:10.0.5-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26385"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94601" version="1" comment="firefox is earlier than 0:10.0.5-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26678"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93853" version="1" comment="xulrunner-devel is earlier than 0:10.0.5-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93805" version="1" comment="firefox is earlier than 0:10.0.5-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26449"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93792" version="1" comment="xulrunner is earlier than 0:10.0.5-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93625" version="1" comment="firefox is earlier than 0:10.0.5-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13805"/>
      <state state_ref="oval:org.mitre.oval:ste:26471"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93513" version="1" comment="xulrunner-devel is earlier than 0:10.0.5-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:26449"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93267" version="1" comment="xulrunner is earlier than 0:10.0.5-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:26449"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97565" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.15-2.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:27137"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97163" version="1" comment="xulrunner is earlier than 0:1.9.2.15-2.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:27137"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137891" version="1" comment="xulrunner is earlier than 0:1.9.2.15-2.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15057"/>
      <state state_ref="oval:org.mitre.oval:ste:38180"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137776" version="1" comment="xulrunner-debuginfo is earlier than 0:1.9.2.15-2.el6_0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:43432"/>
      <state state_ref="oval:org.mitre.oval:ste:38172"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137088" version="1" comment="xulrunner-devel is earlier than 0:1.9.2.15-2.el5_6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15100"/>
      <state state_ref="oval:org.mitre.oval:ste:38180"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97815" version="1" comment="policycoreutils-sandbox is earlier than 0:2.0.83-19.8.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29961"/>
      <state state_ref="oval:org.mitre.oval:ste:26836"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97752" version="1" comment="policycoreutils-python is earlier than 0:2.0.83-19.8.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29975"/>
      <state state_ref="oval:org.mitre.oval:ste:26836"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97730" version="1" comment="policycoreutils-newrole is earlier than 0:2.0.83-19.8.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30176"/>
      <state state_ref="oval:org.mitre.oval:ste:26836"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97725" version="1" comment="selinux-policy-mls is earlier than 0:3.7.19-54.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15143"/>
      <state state_ref="oval:org.mitre.oval:ste:26302"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97672" version="1" comment="policycoreutils-gui is earlier than 0:2.0.83-19.8.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30155"/>
      <state state_ref="oval:org.mitre.oval:ste:26836"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97646" version="1" comment="selinux-policy is earlier than 0:3.7.19-54.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15111"/>
      <state state_ref="oval:org.mitre.oval:ste:26302"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97625" version="1" comment="selinux-policy-minimum is earlier than 0:3.7.19-54.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30075"/>
      <state state_ref="oval:org.mitre.oval:ste:26302"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97211" version="1" comment="selinux-policy-targeted is earlier than 0:3.7.19-54.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14731"/>
      <state state_ref="oval:org.mitre.oval:ste:26302"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97197" version="1" comment="policycoreutils is earlier than 0:2.0.83-19.8.el6_0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30035"/>
      <state state_ref="oval:org.mitre.oval:ste:26836"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:96873" version="1" comment="selinux-policy-doc is earlier than 0:3.7.19-54.el6_0.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30265"/>
      <state state_ref="oval:org.mitre.oval:ste:26302"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98305" version="1" comment="system-config-firewall-tui is earlier than 0:1.2.27-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30178"/>
      <state state_ref="oval:org.mitre.oval:ste:27076"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98159" version="1" comment="system-config-firewall-base is earlier than 0:1.2.27-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29780"/>
      <state state_ref="oval:org.mitre.oval:ste:27076"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98026" version="1" comment="system-config-printer-udev is earlier than 0:1.1.16-17.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30057"/>
      <state state_ref="oval:org.mitre.oval:ste:26761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97880" version="1" comment="system-config-printer-libs is earlier than 0:1.1.16-17.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30005"/>
      <state state_ref="oval:org.mitre.oval:ste:26761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97761" version="1" comment="system-config-printer is earlier than 0:1.1.16-17.el6_1.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30284"/>
      <state state_ref="oval:org.mitre.oval:ste:26761"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97420" version="1" comment="system-config-firewall is earlier than 0:1.2.27-3.el6_1.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:30316"/>
      <state state_ref="oval:org.mitre.oval:ste:27076"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:95039" version="1" comment="thunderbird is earlier than 0:10.0.5-2.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:25850"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94763" version="1" comment="thunderbird is earlier than 0:10.0.5-2.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26292"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93540" version="1" comment="thunderbird is earlier than 0:10.0.5-2.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26627"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93405" version="1" comment="thunderbird is earlier than 0:10.0.5-2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:25969"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98301" version="1" comment="libpng-static is earlier than 2:1.2.46-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29459"/>
      <state state_ref="oval:org.mitre.oval:ste:27345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:98214" version="1" comment="libpng is earlier than 2:1.2.46-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:952"/>
      <state state_ref="oval:org.mitre.oval:ste:27345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97740" version="1" comment="libpng-devel is earlier than 2:1.2.46-1.el6_1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:951"/>
      <state state_ref="oval:org.mitre.oval:ste:27345"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93009" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.31-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:26418"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92776" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.31-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:26418"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92754" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.31-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:26418"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92751" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.31-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:26418"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92743" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.31-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:26418"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92712" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.31-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:26418"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92788" version="1" comment="libxml2-static is earlier than 0:2.7.6-4.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28876"/>
      <state state_ref="oval:org.mitre.oval:ste:26421"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92730" version="1" comment="libxml2-devel is earlier than 0:2.7.6-4.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14212"/>
      <state state_ref="oval:org.mitre.oval:ste:26421"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92572" version="1" comment="libxml2-python is earlier than 0:2.7.6-4.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13780"/>
      <state state_ref="oval:org.mitre.oval:ste:26421"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92378" version="1" comment="libxml2 is earlier than 0:2.7.6-4.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14133"/>
      <state state_ref="oval:org.mitre.oval:ste:26421"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93040" version="1" comment="libvorbis-devel-docs is earlier than 1:1.2.3-4.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29439"/>
      <state state_ref="oval:org.mitre.oval:ste:26398"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92964" version="1" comment="libvorbis is earlier than 1:1.1.2-3.el5_7.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14657"/>
      <state state_ref="oval:org.mitre.oval:ste:26484"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92940" version="1" comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_7.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14840"/>
      <state state_ref="oval:org.mitre.oval:ste:26484"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92918" version="1" comment="libvorbis-devel is earlier than 1:1.2.3-4.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14840"/>
      <state state_ref="oval:org.mitre.oval:ste:26398"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92836" version="1" comment="libvorbis is earlier than 1:1.2.3-4.el6_2.1" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14657"/>
      <state state_ref="oval:org.mitre.oval:ste:26398"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92747" version="1" comment="flash-plugin is earlier than 0:10.3.183.18-1.el5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:26377"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92529" version="1" comment="flash-plugin is earlier than 0:10.3.183.18-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:26108"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93358" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:26151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93104" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:26151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93089" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:26151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92942" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:26151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92894" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:26151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92854" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:26151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92824" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.1-1jpp.5.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:26151"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137901" version="1" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.10.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14584"/>
      <state state_ref="oval:org.mitre.oval:ste:37973"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137870" version="1" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.10.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14233"/>
      <state state_ref="oval:org.mitre.oval:ste:37973"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137830" version="1" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.10.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14915"/>
      <state state_ref="oval:org.mitre.oval:ste:37973"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137818" version="1" comment="java-1.6.0-ibm is earlier than 1:1.6.0.10.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15019"/>
      <state state_ref="oval:org.mitre.oval:ste:37973"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137766" version="1" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.10.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15033"/>
      <state state_ref="oval:org.mitre.oval:ste:37973"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137749" version="1" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.10.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15027"/>
      <state state_ref="oval:org.mitre.oval:ste:37973"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137383" version="1" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.10.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14927"/>
      <state state_ref="oval:org.mitre.oval:ste:37973"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:136938" version="1" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.10.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14715"/>
      <state state_ref="oval:org.mitre.oval:ste:37973"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93865" version="1" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.33-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15162"/>
      <state state_ref="oval:org.mitre.oval:ste:26048"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93812" version="1" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.33-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14923"/>
      <state state_ref="oval:org.mitre.oval:ste:26048"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93718" version="1" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.33-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14712"/>
      <state state_ref="oval:org.mitre.oval:ste:26048"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93441" version="1" comment="java-1.6.0-sun is earlier than 1:1.6.0.33-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14936"/>
      <state state_ref="oval:org.mitre.oval:ste:26048"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93383" version="1" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.33-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14967"/>
      <state state_ref="oval:org.mitre.oval:ste:26048"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93110" version="1" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.33-1jpp.1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14769"/>
      <state state_ref="oval:org.mitre.oval:ste:26048"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93370" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:26461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93293" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:26461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93022" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:26461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92960" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:26461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92763" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:26461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92581" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:26461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92405" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.1-1jpp.2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:26461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137936" version="1" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.13.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14789"/>
      <state state_ref="oval:org.mitre.oval:ste:37866"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137906" version="1" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.13.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14918"/>
      <state state_ref="oval:org.mitre.oval:ste:37866"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137849" version="1" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.13.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14643"/>
      <state state_ref="oval:org.mitre.oval:ste:37866"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137737" version="1" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.13.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14795"/>
      <state state_ref="oval:org.mitre.oval:ste:37866"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137619" version="1" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.13.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14760"/>
      <state state_ref="oval:org.mitre.oval:ste:37866"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137615" version="1" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.13.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14824"/>
      <state state_ref="oval:org.mitre.oval:ste:37866"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137436" version="1" comment="java-1.5.0-ibm is earlier than 1:1.5.0.13.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14898"/>
      <state state_ref="oval:org.mitre.oval:ste:37866"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137286" version="1" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.13.1-1jpp.1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14679"/>
      <state state_ref="oval:org.mitre.oval:ste:37866"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93426" version="1" comment="php-recode is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29111"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93422" version="1" comment="php-xmlrpc is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93416" version="1" comment="php-embedded is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28613"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93412" version="1" comment="php-tidy is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28881"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93408" version="1" comment="php-common is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93407" version="1" comment="php-pdo is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93404" version="1" comment="php-process is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28714"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93403" version="1" comment="php-enchant is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28929"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93368" version="1" comment="php-mbstring is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93366" version="1" comment="php-common is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14841"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93363" version="1" comment="php-soap is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93285" version="1" comment="php-gd is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93282" version="1" comment="php-snmp is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93274" version="1" comment="php-ldap is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93254" version="1" comment="php-pdo is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14154"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93229" version="1" comment="php-cli is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93223" version="1" comment="php is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93207" version="1" comment="php-bcmath is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93201" version="1" comment="php-odbc is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93200" version="1" comment="php-mysql is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93197" version="1" comment="php-odbc is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14183"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93193" version="1" comment="php-devel is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93181" version="1" comment="php-dba is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93179" version="1" comment="php-ncurses is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14227"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93170" version="1" comment="php-imap is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93158" version="1" comment="php-devel is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13492"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93157" version="1" comment="php-pspell is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29329"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93142" version="1" comment="php-pgsql is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93114" version="1" comment="php-intl is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29069"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93111" version="1" comment="php-soap is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14366"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93094" version="1" comment="php-bcmath is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14639"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93077" version="1" comment="php-xml is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93070" version="1" comment="php-dba is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14512"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93058" version="1" comment="php-snmp is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14508"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93019" version="1" comment="php-pgsql is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14148"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92988" version="1" comment="php-zts is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29304"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92982" version="1" comment="php-xml is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14560"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92979" version="1" comment="php is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14294"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92905" version="1" comment="php-mysql is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14080"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92904" version="1" comment="php-xmlrpc is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14445"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92879" version="1" comment="php-gd is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14335"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92791" version="1" comment="php-cli is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14922"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92648" version="1" comment="php-mbstring is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13746"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92622" version="1" comment="php-imap is earlier than 0:5.1.6-34.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14250"/>
      <state state_ref="oval:org.mitre.oval:ste:26594"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92434" version="1" comment="php-ldap is earlier than 0:5.3.3-3.el6_2.8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14375"/>
      <state state_ref="oval:org.mitre.oval:ste:26629"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94945" version="1" comment="thunderbird is earlier than 0:10.0.3-1.el5.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26537"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94449" version="1" comment="thunderbird is earlier than 0:10.0.3-1.el6.centos" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26696"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93140" version="1" comment="thunderbird is earlier than 0:10.0.3-1.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26383"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93120" version="1" comment="thunderbird is earlier than 0:10.0.3-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14449"/>
      <state state_ref="oval:org.mitre.oval:ste:26456"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93393" version="1" comment="ImageMagick-c++ is earlier than 0:6.5.4.7-6.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13475"/>
      <state state_ref="oval:org.mitre.oval:ste:26376"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93316" version="1" comment="ImageMagick-doc is earlier than 0:6.5.4.7-6.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29685"/>
      <state state_ref="oval:org.mitre.oval:ste:26376"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93295" version="1" comment="ImageMagick-devel is earlier than 0:6.5.4.7-6.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13484"/>
      <state state_ref="oval:org.mitre.oval:ste:26376"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93284" version="1" comment="ImageMagick is earlier than 0:6.5.4.7-6.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13854"/>
      <state state_ref="oval:org.mitre.oval:ste:26376"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92812" version="1" comment="ImageMagick-perl is earlier than 0:6.5.4.7-6.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14270"/>
      <state state_ref="oval:org.mitre.oval:ste:26376"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92705" version="1" comment="ImageMagick-c++-devel is earlier than 0:6.5.4.7-6.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14240"/>
      <state state_ref="oval:org.mitre.oval:ste:26376"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93801" version="1" comment="python is earlier than 0:2.6.6-29.el6_2.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14556"/>
      <state state_ref="oval:org.mitre.oval:ste:26626"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93765" version="1" comment="tkinter is earlier than 0:2.6.6-29.el6_2.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14092"/>
      <state state_ref="oval:org.mitre.oval:ste:26626"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93677" version="1" comment="python-tools is earlier than 0:2.6.6-29.el6_2.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14208"/>
      <state state_ref="oval:org.mitre.oval:ste:26626"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93602" version="1" comment="python-test is earlier than 0:2.6.6-29.el6_2.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29582"/>
      <state state_ref="oval:org.mitre.oval:ste:26626"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93570" version="1" comment="python-libs is earlier than 0:2.6.6-29.el6_2.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29635"/>
      <state state_ref="oval:org.mitre.oval:ste:26626"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93026" version="1" comment="python-devel is earlier than 0:2.6.6-29.el6_2.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14166"/>
      <state state_ref="oval:org.mitre.oval:ste:26626"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93576" version="1" comment="openssl is earlier than 0:1.0.0-20.el6_2.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:26573"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93567" version="1" comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:26429"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93493" version="1" comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:26429"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93414" version="1" comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:26573"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93399" version="1" comment="openssl is earlier than 0:0.9.8e-22.el5_8.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:26429"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92832" version="1" comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:26573"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92594" version="1" comment="openssl-static is earlier than 0:1.0.0-20.el6_2.5" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:26573"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93978" version="1" comment="389-ds-base is earlier than 0:1.2.10.2-15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28953"/>
      <state state_ref="oval:org.mitre.oval:ste:26628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93907" version="1" comment="389-ds-base-devel is earlier than 0:1.2.10.2-15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29162"/>
      <state state_ref="oval:org.mitre.oval:ste:26628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93848" version="1" comment="389-ds-base-libs is earlier than 0:1.2.10.2-15.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28949"/>
      <state state_ref="oval:org.mitre.oval:ste:26628"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94890" version="1" comment="kdelibs-common is earlier than 6:4.3.4-19.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29368"/>
      <state state_ref="oval:org.mitre.oval:ste:26238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94853" version="1" comment="kdelibs is earlier than 6:4.3.4-19.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13933"/>
      <state state_ref="oval:org.mitre.oval:ste:26238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94687" version="1" comment="kdelibs-devel is earlier than 6:4.3.4-19.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14126"/>
      <state state_ref="oval:org.mitre.oval:ste:26238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94632" version="1" comment="kdelibs-apidocs is earlier than 6:4.3.4-19.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15138"/>
      <state state_ref="oval:org.mitre.oval:ste:26238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:97924" version="1" comment="sudo is earlier than 0:1.7.4p5-5.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14246"/>
      <state state_ref="oval:org.mitre.oval:ste:27177"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93641" version="1" comment="flash-plugin is earlier than 0:10.3.183.20-1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:26644"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:137696" version="1" comment="flash-plugin is earlier than 0:10.3.183.20-1.el5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14752"/>
      <state state_ref="oval:org.mitre.oval:ste:38099"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94717" version="1" comment="bind-sdb is earlier than 32:9.8.2-0.10.rc1.el6_3.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14433"/>
      <state state_ref="oval:org.mitre.oval:ste:26666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94704" version="1" comment="bind-libs is earlier than 32:9.8.2-0.10.rc1.el6_3.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14348"/>
      <state state_ref="oval:org.mitre.oval:ste:26666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94544" version="1" comment="bind-utils is earlier than 32:9.8.2-0.10.rc1.el6_3.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14263"/>
      <state state_ref="oval:org.mitre.oval:ste:26666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94526" version="1" comment="bind-chroot is earlier than 32:9.8.2-0.10.rc1.el6_3.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14363"/>
      <state state_ref="oval:org.mitre.oval:ste:26666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94467" version="1" comment="bind-devel is earlier than 32:9.8.2-0.10.rc1.el6_3.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14242"/>
      <state state_ref="oval:org.mitre.oval:ste:26666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94354" version="1" comment="bind is earlier than 32:9.8.2-0.10.rc1.el6_3.6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14143"/>
      <state state_ref="oval:org.mitre.oval:ste:26666"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94950" version="1" comment="libtiff is earlier than 0:3.9.4-9.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:26686"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94861" version="1" comment="libtiff-devel is earlier than 0:3.9.4-9.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:26686"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94836" version="1" comment="libtiff-static is earlier than 0:3.9.4-9.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29708"/>
      <state state_ref="oval:org.mitre.oval:ste:26686"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94475" version="1" comment="libtiff is earlier than 0:3.8.2-18.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14341"/>
      <state state_ref="oval:org.mitre.oval:ste:26684"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94221" version="1" comment="libtiff-devel is earlier than 0:3.8.2-18.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14174"/>
      <state state_ref="oval:org.mitre.oval:ste:26684"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93450" version="1" comment="kernel-debug-devel is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15023"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93444" version="1" comment="kernel-firmware is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29194"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93442" version="1" comment="kernel-headers is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14830"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93410" version="1" comment="kernel-devel is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13732"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93231" version="1" comment="kernel-debug is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14957"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93178" version="1" comment="kernel-bootwrapper is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29229"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93176" version="1" comment="kernel-doc is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13422"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93062" version="1" comment="python-perf is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28972"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93053" version="1" comment="kernel-kdump-devel is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14761"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92992" version="1" comment="kernel is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14285"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92811" version="1" comment="kernel-kdump is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14801"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92805" version="1" comment="perf is earlier than 0:2.6.32-220.17.1.el6" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29062"/>
      <state state_ref="oval:org.mitre.oval:ste:26357"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94197" version="1" comment="krb5 is earlier than 0:1.9-33.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14120"/>
      <state state_ref="oval:org.mitre.oval:ste:26245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94184" version="1" comment="krb5-workstation is earlier than 0:1.9-33.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14279"/>
      <state state_ref="oval:org.mitre.oval:ste:26245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94171" version="1" comment="krb5-pkinit-openssl is earlier than 0:1.9-33.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29392"/>
      <state state_ref="oval:org.mitre.oval:ste:26245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94127" version="1" comment="krb5-server is earlier than 0:1.9-33.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14452"/>
      <state state_ref="oval:org.mitre.oval:ste:26245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93972" version="1" comment="krb5-devel is earlier than 0:1.9-33.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14100"/>
      <state state_ref="oval:org.mitre.oval:ste:26245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93882" version="1" comment="krb5-libs is earlier than 0:1.9-33.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14395"/>
      <state state_ref="oval:org.mitre.oval:ste:26245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93747" version="1" comment="krb5-server-ldap is earlier than 0:1.9-33.el6_3.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29451"/>
      <state state_ref="oval:org.mitre.oval:ste:26245"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94552" version="1" comment="dbus-devel is earlier than 1:1.2.24-7.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14425"/>
      <state state_ref="oval:org.mitre.oval:ste:26689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94521" version="1" comment="dbus-x11 is earlier than 1:1.2.24-7.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14132"/>
      <state state_ref="oval:org.mitre.oval:ste:26689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94520" version="1" comment="dbus is earlier than 1:1.2.24-7.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14213"/>
      <state state_ref="oval:org.mitre.oval:ste:26689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94496" version="1" comment="dbus-doc is earlier than 1:1.2.24-7.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29899"/>
      <state state_ref="oval:org.mitre.oval:ste:26689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94488" version="1" comment="dbus-libs is earlier than 1:1.2.24-7.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15234"/>
      <state state_ref="oval:org.mitre.oval:ste:26689"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94870" version="1" comment="openssl098e is earlier than 0:0.9.8e-17.el6.centos.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29469"/>
      <state state_ref="oval:org.mitre.oval:ste:26739"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93396" version="1" comment="openssl097a is earlier than 0:0.9.7a-11.el5_8.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14181"/>
      <state state_ref="oval:org.mitre.oval:ste:26086"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93345" version="1" comment="openssl is earlier than 0:0.9.8e-22.el5_8.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:25661"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93327" version="1" comment="openssl-perl is earlier than 0:0.9.8e-22.el5_8.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:25661"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93186" version="1" comment="openssl-perl is earlier than 0:1.0.0-20.el6_2.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14122"/>
      <state state_ref="oval:org.mitre.oval:ste:26555"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93183" version="1" comment="openssl098e is earlier than 0:0.9.8e-17.el6_2.2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29469"/>
      <state state_ref="oval:org.mitre.oval:ste:26625"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93154" version="1" comment="openssl is earlier than 0:1.0.0-20.el6_2.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13882"/>
      <state state_ref="oval:org.mitre.oval:ste:26555"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93126" version="1" comment="openssl-devel is earlier than 0:1.0.0-20.el6_2.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:26555"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92825" version="1" comment="openssl-static is earlier than 0:1.0.0-20.el6_2.4" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28921"/>
      <state state_ref="oval:org.mitre.oval:ste:26555"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92802" version="1" comment="openssl-devel is earlier than 0:0.9.8e-22.el5_8.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:13920"/>
      <state state_ref="oval:org.mitre.oval:ste:25661"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94537" version="1" comment="postgresql84-contrib is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15329"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94531" version="1" comment="postgresql-server is earlier than 0:8.4.13-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14158"/>
      <state state_ref="oval:org.mitre.oval:ste:26654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94530" version="1" comment="postgresql84-plpython is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15356"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94506" version="1" comment="postgresql84-docs is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15371"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94490" version="1" comment="postgresql-libs is earlier than 0:8.4.13-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14383"/>
      <state state_ref="oval:org.mitre.oval:ste:26654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94457" version="1" comment="postgresql is earlier than 0:8.4.13-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14586"/>
      <state state_ref="oval:org.mitre.oval:ste:26654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94445" version="1" comment="postgresql-pltcl is earlier than 0:8.4.13-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29636"/>
      <state state_ref="oval:org.mitre.oval:ste:26654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94410" version="1" comment="postgresql-test is earlier than 0:8.4.13-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14367"/>
      <state state_ref="oval:org.mitre.oval:ste:26654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94376" version="1" comment="postgresql84-server is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15020"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94344" version="1" comment="postgresql84-devel is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15349"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94332" version="1" comment="postgresql-plperl is earlier than 0:8.4.13-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29499"/>
      <state state_ref="oval:org.mitre.oval:ste:26654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94296" version="1" comment="postgresql84-plperl is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14866"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94264" version="1" comment="postgresql84-python is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15270"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94217" version="1" comment="postgresql84 is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15160"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94212" version="1" comment="postgresql84-libs is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15091"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94185" version="1" comment="postgresql-plpython is earlier than 0:8.4.13-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29607"/>
      <state state_ref="oval:org.mitre.oval:ste:26654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94123" version="1" comment="postgresql84-pltcl is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15092"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94038" version="1" comment="postgresql84-test is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15176"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93983" version="1" comment="postgresql-devel is earlier than 0:8.4.13-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14290"/>
      <state state_ref="oval:org.mitre.oval:ste:26654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93982" version="1" comment="postgresql-docs is earlier than 0:8.4.13-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14365"/>
      <state state_ref="oval:org.mitre.oval:ste:26654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93946" version="1" comment="postgresql-contrib is earlier than 0:8.4.13-1.el6_3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14293"/>
      <state state_ref="oval:org.mitre.oval:ste:26654"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93867" version="1" comment="postgresql84-tcl is earlier than 0:8.4.13-1.el5_8" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:14440"/>
      <state state_ref="oval:org.mitre.oval:ste:26483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94482" version="1" comment="java-1.7.0-openjdk-devel is earlier than 1:1.7.0.5-2.2.1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29032"/>
      <state state_ref="oval:org.mitre.oval:ste:26527"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94393" version="1" comment="java-1.7.0-openjdk-demo is earlier than 1:1.7.0.5-2.2.1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29256"/>
      <state state_ref="oval:org.mitre.oval:ste:26527"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94382" version="1" comment="java-1.7.0-openjdk-javadoc is earlier than 1:1.7.0.5-2.2.1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29000"/>
      <state state_ref="oval:org.mitre.oval:ste:26527"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94160" version="1" comment="java-1.7.0-openjdk-src is earlier than 1:1.7.0.5-2.2.1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28946"/>
      <state state_ref="oval:org.mitre.oval:ste:26527"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:94070" version="1" comment="java-1.7.0-openjdk is earlier than 1:1.7.0.5-2.2.1.el6_3.3" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28860"/>
      <state state_ref="oval:org.mitre.oval:ste:26527"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93076" version="1" comment="libpng-static is earlier than 2:1.2.46-2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29489"/>
      <state state_ref="oval:org.mitre.oval:ste:26466"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93067" version="1" comment="libpng-devel is earlier than 2:1.2.46-2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:951"/>
      <state state_ref="oval:org.mitre.oval:ste:26466"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92956" version="1" comment="libpng is earlier than 2:1.2.46-2.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:952"/>
      <state state_ref="oval:org.mitre.oval:ste:26466"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92710" version="1" comment="libpng is earlier than 2:1.2.10-15.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:952"/>
      <state state_ref="oval:org.mitre.oval:ste:26453"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:92474" version="1" comment="libpng-devel is earlier than 2:1.2.10-15.el5_7" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:951"/>
      <state state_ref="oval:org.mitre.oval:ste:26453"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93346" version="1" comment="samba-doc is earlier than 0:3.5.10-115.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:29416"/>
      <state state_ref="oval:org.mitre.oval:ste:26279"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93336" version="1" comment="samba-domainjoin-gui is earlier than 0:3.5.10-115.el6_2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:28867"/>
      <state state_ref="oval:org.mitre.oval:ste:26279"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:93323" version="1" comment="libsmbclient is earlier than 0:3.0.33-3.39.el5_8" check_existence="at_least_o